Session Detection and Inference

By integrating session detection and analysis in network devices, the security and performance of client-server communication are improved by monitoring and managing session information, addressing the issue of compromised session security.

CN116074136BActive Publication Date: 2025-07-15HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210419654.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-10-30
Filing Date
2022-04-20
Publication Date
2025-07-15
Estimated Expiration
2042-04-20

AI Technical Summary

Technical Problem

In client-server communication, the visibility of session information and service flows is insufficient, resulting in network devices being vulnerable to various session-based attacks. Existing tools have very little visibility of session information in network devices, affecting security and performance.

Method used

Introduce the intelligence of session detection and session analysis in network devices, track the sequence number through TCP header information, generate session statistics information, realize monitoring and management of session frequency and average session duration, and support load balancing and abnormal behavior detection.

Benefits of technology

It improves the information transmission performance of client-server communication, reduces the risk of information service flow, prevents the occurrence of failures and malicious programs, and enhances the security and management capabilities of network equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116074136B_ABST
    Figure CN116074136B_ABST
Patent Text Reader

Abstract

The present invention relates to session detection and inference. A session is a core component of communication that can include communication between, for example, a client device and a server in a communication system. Network devices can be used to monitor and analyze session information transmitted in client-server communication. Visibility into the session information and traffic flow of network devices is crucial for improving the performance and security of network devices and the transmission of information in client-server communication. The lack of visibility into session information can reduce security, leading to viruses, malware, and faults.
Need to check novelty before this filing date? Find Prior Art

Description

Background

[0001] A session is a temporary and interactive information exchange between two or more systems. Some sessions involve a client and a server, while other sessions involve two or more communication devices. A common type of client / server session is a Web or HTTP session. A communication session can involve more than one message in each direction. During a session, at least one communicating party needs to maintain current state information and save information about the session history to be able to communicate. Before data can be transferred between systems, a session needs to be established in connection-oriented communication.

[0002] However, the security between the parties participating in a session can be compromised. For example, a third party can hijack or otherwise access the identification information of a session such as a cookie. One way to access such identification information includes source-routed Internet Protocol (IP) packets, where the IP packets between two parties are diverted to a third party's machine. Another way is for a third party to eavesdrop on the communication between two parties. Yet another way is for a third party to masquerade as one of the two parties and send commands to gain access to the communication between the two parties. Brief Description of the Drawings

[0003] In accordance with one or more various examples, the present disclosure is described in detail with reference to the following drawings. The drawings are provided for illustrative purposes only and depict typical or exemplary examples.

[0004] Figure 1 is an exemplary illustration of a computing system that authenticates and authorizes a client device to access a network in a streamlined manner according to an example described in the present disclosure.

[0005] Figure 2 is an exemplary illustration of an example session operation according to various examples of the present disclosure.

[0006] Figure 3 is an exemplary flowchart showing how to detect a session in client-server communication and assign a sequence number to each stage of the session according to various examples of the present disclosure.

[0007] Figure 4 is an exemplary flowchart showing how to establish a new session in client-server communication according to various examples of the present disclosure.

[0008] Figure 5 is an exemplary flowchart showing how to classify a session based on statistical generation information of session information according to various examples of the present disclosure.

[0009] Figure 6 is a block diagram of an example computer system in which various examples of the present disclosure can be implemented.

[0010] The accompanying drawings are not exhaustive and do not limit the present disclosure to the exact forms disclosed. Detailed Description

[0011] A session is a core component of communication that can include communication between, for example, a client device and a server in a communication system. A session is established at a certain point in time and ends at a later point in time. A session can start when a user logs in or accesses a computer system, network, or software service. A session can end when the user logs out of the service, leaves the network, or shuts down the computer system. An established communication session can involve more than one message being sent in each direction. During a session, session information related to user activity can be stored. The stored session information can be used to retrieve or view data from various computing systems. Visibility into the session information and traffic flow of network devices in client-server communication is key to improving the performance and security of network devices by allowing for the management of session information and traffic flow. The lack of visibility into session information and traffic flow reduces the security of network devices and applications, making network devices or applications vulnerable to various session-based attacks. Currently, there are tools for managing sessions at the client or server side, but visibility into session information in network devices is rarely available. Therefore, there is a need for visibility into the session information and traffic flow of network devices in client-server communication.

[0012] To address this need for visibility into session information and traffic flow, one solution is to introduce the intelligence of session detection and session analysis in network devices in client-server communication. Session detection and session analysis can be used to track sequence numbers by using the Transmission Control Protocol (TCP) header information of each message being sent within the client-server communication. This solution can also use session detection and analysis information to generate statistical information about the sessions occurring within the client-server communication, such as the frequency of sessions and the average session duration of sessions. The system can adaptively collect data on session information while performing load balancing with or without external intervention.

[0013] This document describes solutions to the above problems. A computing system can provide a systematic way to obtain and manage session information at a network device. In various examples, the computing system can include a network device in a client-server communication. In some examples, the client and / or the server can be the Internet. In some cases, the client and / or the server can be a computing device, which can include, for example, a computer or a mobile device. In some examples, the network device can be a switch, an access point, or a router. In some examples, the network device can be included in multiple different client-server communications where multiple sessions can occur simultaneously. When a session is detected in a client-server communication, the network device can send instructions to obtain session information without interrupting the user activities ongoing during the session. In this way, the network device can monitor, analyze, and manage the traffic of various session information and data in the client-server communication. In some examples, the network device can monitor session information and traffic by sending instructions and perform load balancing on the session information to improve the performance of information transmission and reduce the traffic of information in the client-server communication. Monitoring and analyzing session information in the client-server communication can prevent failures and malicious programs by flagging any problems and implementing solutions once problems occur, thereby proactively preventing security breaches and damages. These and other features of the examples of the present disclosure are discussed herein.

[0014] Figure 1 is an exemplary illustration of a computing system 110 that includes any one or more computing components that can include a server 111, a router 120, a switch 122, a network controller 124, an access point 126, and a DHCP server 128. In some examples, the router 120 can be associated with a firewall 121. In some examples, the server 111 can include a Remote Authentication Dial-In User Service (RADIUS) server or an authentication server. The router 120 can also include a database or cache 112 (hereinafter referred to as "database") or be associated with a database or cache 112 that stores attributes of specific client devices, servers, and access control lists or policies associated with client devices (such as client devices 150, 160, and 170) connected to the network via the access point 126. Although in Figure 1Only three client devices are shown, but any number of client devices may be connected via access point 126. Database 112 may be integrated or embedded within router 120 or spatially separated from router 120. The access control list may be stored as a file and / or may be indexed. In some examples, the access control list or policy may include specific access levels and / or access privileges assigned to each client device according to the group or classification to which the client device belongs. For example, the access privileges may indicate a subset (e.g., part or all) of data resources, such as specific data servers, databases, platforms, objects, file directories or files to which each client device is authorized to access, specific protocols (e.g., Hypertext Transfer Protocol (HTTP) or File Transfer Protocol (FTP)) that each client device may utilize to access the data resources, the transmission speed or rate to be provided to each client device, one or more provider specified attributes (VSA), and / or a specific VLAN to be assigned to each client device. In some examples, the VSA may include bandwidth on incoming and / or outgoing traffic and download and / or upload speeds. The access control list or policy may be stored in database 112 of router 120 rather than at other computing components such as server 111, such that router 120 may centrally update the access control list or policy and propagate any updates to other computing components in the network. In some examples, switch 122 may include database 114 or be associated with database 114. In some examples, database 114 may include any or all of the information previously described for database 112. Alternatively or additionally, database 114 may include information about different virtual local area networks (VLANs) and information about routing traffic between different VLANs. Database 114 may be integrated or embedded within switch 122 or spatially separated from switch 122.

[0015] Each computing component may include logic that implements instructions to perform the functions of the computing component and one or more hardware processors. Specifically, router 120 may include logic 113 or be associated with logic 113. Logic 113 may receive one or more authentication packets transmitted by the client device via network controller 124. In some examples, network controller 124 may include an access point or wireless local area network (WLAN) controller that manages a WLAN network that may be applied to relatively small WLAN networks. Logic 113 may verify the credentials of the client device. Logic 113 may then decrypt or extract one or more attributes from the authentication packet, which include the media access control (MAC) address of the client device, one or more hardware attributes such as the type of client device (e.g., tablet computer, desktop computer, Internet of Things device), and / or one or more software attributes of the client device.

[0016] Figure 2 It is an example illustration of the example session operation 200 according to various examples of the present disclosure. In some examples, the network of the session operation 200 may include any one or more computing components that may cover client devices 210, network devices 220, network controllers 230, access points 232, and servers 240. Figure 2 Detailed description Figure 1 Specific components will be described in detail while describing the information exchange between components. The client device may be a computing device such as a computer, a mobile phone, a tablet device, etc. The network device 220 may be implemented as Figure 1 the router 120 or the switch 122 as shown. The network device 220 may be a router or a switch configured to connect various computing components in the network, such as client devices 210, network controllers 230, access points 232, and servers 240. The network device 220 may also include or be associated with a database or cache 222 (hereinafter referred to as "database"), and the database or cache 222 stores the attributes of specific client devices and servers, as well as the access control list or policy associated with the client device 210 connected to the network via the access point 232. In some examples, the client device 210 may wirelessly access the Internet via Wi-Fi (e.g., IEEE802.11), Bluetooth (e.g., IEEE 802.15.1), or a cellular connection (e.g., 5G Long-Term Evolution cellular network, etc.) to wirelessly access the server 240 via the network device 220. The server 240 may implement software and / or hardware such as a web server, an application server, a communication server, a database server, etc. The server 240 may access the Internet via Wi-Fi, Bluetooth, a telephone line, or a LAN / WLAN network interface. In other examples, the network device 240 may be an enterprise intranet (e.g., a private network), and the client device 210 may wirelessly access the enterprise intranet via the network device 220 to access data files or other enterprise data. In some cases, the network device 220 may be a network link (e.g., Wi-Fi, an Ethernet port, a router, a switch, etc.) that allows multiple computing components to communicate with each other. The network controller 230 and the access point 232 may be configured to allow computing components in the network, such as the client device 210 and the server 240, to connect via the network device 220. In this example, the network device 220 may establish client-server communication between the client device 210 and the server 240.

[0017] In some examples, session operation 200 may begin when client device 210 is launched, logged in, or accessed. In some examples, session operation 200 may end when client device 210 is shut down, logged out, or no longer accessed. During session operation 200, client device 210 may establish client-server communication with server 240. Network device 220 may be configured to act as a link for establishing client-server communication between client device 210 and server 240. In some examples, client device 210 may send request information 250 to server 240 via network device 220. Server 240 may then send response information 260 back to client device 210 via network device 220. Network device 220 may act as a link for establishing client-server communication and allowing information to be sent back and forth between client device 210 and server 240 during session operation 200. In some examples, request information 250 of session operation 200 may be information searched from browsing the Internet, emails sent via various email clients, files searched stored in a database, etc. Response information 260 of session operation 200 may be information found on the Internet, response emails sent via various email clients, files requested from a database, etc. In some examples, request information 250 and response information 260 may include session information related to activities performed at client device 210 and server 240 during session operation 200. In some examples, network device 220 may read and obtain session information from request information 250 and response information 260 passed during session operation 200. Once network device 220 has read and obtained the session information of request information 250 and response information 260, network device 220 may record and store the session information into database 112. Session information may include source information, destination information, source port, destination port, duration of session operation 200, and / or parameters such as frame length or packet size sent, number of frames or number of packets transmitted, change in size of frames or packets, and / or change in length of frames or packets, packet frequency and frame frequency transmitted during the session. Allowing session information to be stored at network device 220 may allow visibility into the traffic flow, security, and performance of data in client-server communication. In a particular scenario, both parties may have an established communication pattern where the frame length sent generally falls within a specific range. However, if the frame length deviates from that specific range, such deviation may indicate interference or interception by a malicious actor. Analyzing the stored session information may detect abnormal behavior by comparing any of the foregoing parameters or other session information with corresponding thresholds, ranges, or criteria (hereinafter referred to as "thresholds"). For example, abnormal behavior may consist of any of the foregoing parameters or other session information that falls outside the corresponding thresholds or criteria.When the network device 220 detects an abnormal behavior, the network device 220 may collect additional session information. In some examples, the network device 220 may collect additional session information specifically regarding parameters or other session information that fall outside the corresponding thresholds or criteria. For example, if the length of the transmitted frame deviates from a specific range, the network device may collect additional session information specifically regarding the length of the transmitted frame without collecting other information.

[0018] Additionally or optionally, when detecting abnormal behavior, the network device 220 may send an alert to an administrator to provide notification of the abnormal behavior. The administrator may provide feedback in response to the alert to resolve the abnormal behavior. For example, if the administrator receives an alert regarding traffic data congestion in client-server communication, the administrator may send feedback to the network device to perform load balancing. For example, the network device 220 may perform load balancing based on the feedback. In particular, the feedback may indicate that the traffic transmission (e.g., frames or packets) across one session or a subset of sessions may be interleaved, postponed, or delayed, and / or have a lower or higher priority compared to one or more other sessions. In other scenarios, the feedback may indicate that the transmission of a subset or portion of the traffic in one session may be postponed or delayed, and / or have a lower or higher priority compared to one or more other subsets or portions of the traffic in that one session. Thus, the network device 220 may perform load balancing according to the feedback indicating session priorities. Load balancing may include interleaving the transmission of frames or packets within a session such that, at any given time interval, the total amount of traffic transmitted across all sessions is within a threshold traffic volume. If a session is indicated to have a lower priority, the network device 220 may delay the transmission of that one session for load balancing. Additionally or alternatively, the network device 220 may postpone or delay the transmission of a portion of the traffic in one session according to the feedback. The network device 220 may interleave the transmission of frames or packets within a session such that, at any given time interval, the total amount of traffic transmitted across all sessions is within the threshold traffic volume of any given time interval. Thus, the transmission of frames or packets within a particular session or multiple particular sessions, or a subset of frames or packets within a particular session or multiple particular sessions, may be postponed or delayed. Only as an illustrative example, the threshold traffic volume may be 1000 megabytes (MB) per 5-second interval. Thus, in this scenario, the network device 220 may regulate the total amount of traffic transmitted across all sessions to not exceed 100 MB per 5-second interval by selectively delaying or postponing the transmission of frames or packets within a particular session or multiple particular sessions, or a subset of frames or packets within a particular session or multiple particular sessions. Additionally or alternatively, the network device 220 may perform all of the above operations with or without human interaction. For example, the administrator does not have to resolve the abnormal behavior, and the network device may automatically perform load balancing based on any or all session information collected and / or stored.

[0019] Figure 3A computing component 300 is shown that includes one or more hardware processors 302 and a machine-readable storage medium 304 storing a set of machine-readable / machine-executable instructions that, when executed, cause the hardware processors 302 to perform an illustrative method of reducing computing costs while maintaining network services and performance. It should be understood that, unless otherwise specified, within the scope of the various examples discussed herein, there may be additional, fewer, or alternative steps that are performed in a similar or alternative order or in parallel. The computing component 300 may be implemented as Figure 1 a router 120 or a switch 122, and Figure 2 a network device 220. Figure 3 summarizes and further elaborates on some aspects described previously.

[0020] At step 320, the hardware processors 302 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 304 to detect a session in a client-server communication. Before a session can be detected, the client-server communication is first established. When a first message is sent within the client-server communication, a first session is detected and established. In some examples, the session may be a Transmission Control Protocol (TCP) session. In some examples, the client-server communication is a communication between a client device and a server using a network device as a link. Once the first session is established, each message sent in the client-server communication may be represented as a session phase. The message may be a request sent by the client device or a response sent by the server in the client-server communication. Each session may include one or more session phases. In some examples, a session operation may include multiple sessions, where each session includes multiple session phases. In some examples, a single message may be a request sent by the client device or a response sent from the server.

[0021] At step 330, the hardware processors 302 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 304 to assign a sequence number to each session phase of a session operation. In some examples, the first session phase of the first session is assigned an Initial Sequence Number (ISN). In some examples, the ISN is a 32-bit number. In some examples, the ISN is a random number. The ISN is the first sequence number assigned to the first session phase of the session operation. In some examples, each subsequent session phase of the session operation will have a sequence number that is incremented from the sequence number of the previous session phase. The amount by which each subsequent sequence number is incremented from the previous sequence number may vary depending on various factors.

[0022] At step 340, the hardware processor(s) 302 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 304 to add session information for each session stage of a session operation to a cache. In some examples, a network device reads multiple session information of multiple session stages in a session operation and records the multiple session information in the cache. The cache may be a database associated with or embedded in the network device for establishing client-server communication. In some examples, the cache of session information may be shown in Table 1. The session information for each session stage may include a sequence number, duration, source information, destination information, source port, destination port, and frame length of the session information of the session stage of the session operation. The cache of session information may display a list of session information for each session stage that has been established in a single session operation. The first set of session information listed in the cache will be from the first session stage of the session operation, where the sequence number is the ISN. Each subsequent session stage listed in the cache will have a sequence number incremented from the previous session stage. The cache may store multiple session information of multiple session stages of a session operation.

[0023] At step 350, the hardware processor(s) 302 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 304 to determine whether the difference between the sequence number of the current session stage and the sequence number of the previous session stage is greater than a preset magnitude. In some examples, if the difference between the sequence number of the current message or session stage and the sequence number of the previous message or session stage in the current session is greater than the preset magnitude, the current session has ended and a new session is established in the client-server communication. For example, if the preset magnitude is 1000, the sequence number of the current session stage is 2227, and the sequence number of the previous session stage is 1109, then the difference in the sequence numbers is 1118, which is greater than the magnitude of 1000, so the current session has ended and a new session is being established. If the difference between the sequence number of the current message and the sequence number of the previous message in the current session is not greater than the preset magnitude, the current session continues to be active. In some examples, the preset magnitude may be a preset number. In other examples, the preset magnitude may vary periodically or based on various factors. Many variations are possible. If the difference between the sequence number of the current message or session stage and the sequence number of the previous message or session stage in the current session is determined to be greater than the preset magnitude, the hardware processor 302 may proceed to step 320 to start a new session. Otherwise, the hardware processor 302 may proceed to step 330, where the current session continues but at a different session stage or message. Subsequently, the hardware processor may obtain subsequent entries of the session stage during the session operation and repeat the foregoing steps for each subsequent entry until the session operation has ended.

[0024] Figure 4 A computing component 400 is shown that includes one or more hardware processors 402 and a machine-readable storage medium 404 storing a set of machine-readable / machine-executable instructions that, when executed, cause the (multiple) hardware processors 402 to perform an illustrative method of reducing computing costs while maintaining network services and performance. It should be understood that, unless otherwise specified, within the scope of the various examples described herein, there may be additional, fewer, or alternative steps that are performed in a similar or alternative order or in parallel. The computing component 400 may be implemented as Figure 1 a router 120 or a switch 122 of Figure 2 a network device 220 of Figure 3 and a computing component 300 of Figure 4 summarizes and further elaborates on some of the aspects described previously.

[0025] At step 408, the hardware processor(s) 402 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 404 to initiate a new session in client-server communication. Client-server communication is established before a session can be detected. When a first message is sent within the client-server communication, a first session is detected and established. In some examples, the session may be a Transmission Control Protocol (TCP) session. In some examples, the client-server communication is between a client device and a server using a network device as a link. In some examples, the network device may be a router or a switch. Once the first session is established, each message sent in the client-server communication may be represented as a session phase. In some examples, the first session is one or more messages sent between the client device and the server. In some examples, the one or more messages may be one or more requests sent by the client device, one or more responses sent from the server, or a combination of one or more requests and responses. Each session may include one or more session phases. In some examples, session operations may include multiple sessions, where each session includes multiple session phases. In some examples, a single message may be a request sent by the client device or a response sent from the server. In some examples, the network device may be a router or a switch. In some examples, the first session is one or more messages sent between the client device and the server. In some examples, the one or more messages may be one (or more) requests sent by the client device, one or more responses sent from the server, or a combination of one or more requests and responses. In some examples, each message sent between the client device and the server has a sequence number. In some examples, the sequence number is a 32-bit number. In some examples, the sequence number is a random number. Many variations are possible. In some examples, each message sent in the client-server communication of the first session has a sequence number. The sequence number of the current message sent in the client-server communication is an increment of the sequence number of the previously sent message. If the difference between the sequence number of the current message and the sequence number of the previous message in the first session is greater than a preset magnitude, the first session has ended and a new session is established for the client-server communication. If the difference between the sequence number of the current message and the sequence number of the previous message in the first session is not greater than the preset magnitude, the first session remains active and the current session is maintained.

[0026] At step 410, the hardware processor(s) 402 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 404 to start a timer for a new session. In some examples, the timer may provide the start time of the new session. For example, the new session may be a first session, and the timer may provide a start time of 9:36:00, where the first session is established in the communication between the client device and the server. In some examples, the timer may provide the current time of the current session. In some examples, the current time of the current session is the time of a new message sent in the client-server communication. For example, if the current session is the first session, the timer may provide a current time of 10:21:00, where the new message is sent in the client-server communication. The duration of the current session may be determined. The duration of the current session may be the difference between the current time and the start time of the current session. For example, the duration of the first session may be the difference between the current time of 10:21:00 and the start time of 9:36:00, which is 45 minutes. In some examples, the duration is updated with each new message sent in the first session of the client-server communication. In some examples, the duration of each message sent in the first session between the client device and the server may be based on the session information of that message.

[0027] At step 412, the hardware processor(s) 402 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 404 to obtain statistical generation information for the session. In some examples, the statistical generation information is obtained along with the session information of the current session phase. The statistical generation information and the session information may be obtained at a network device. The network device may be a router or a switch. In other examples, the statistical generation information is based on the session information of multiple session phases. In some instances, as shown in Table 2, the statistical generation information may include a session number, a sequence number, a session start time, a session duration, a session count, an average duration, a minimum duration, a maximum duration, a standard deviation of the duration, a session frequency, and a session type. In some examples, the session type may include a short-term session or a long-term session. In some examples, a long-term session is any session with a duration greater than a preset duration threshold. A short-term session is any session with a duration not greater than the preset duration threshold. In some examples, the preset duration threshold may be a preset number. In other examples, the preset duration threshold may vary periodically or based on various factors. Many variations are possible. The statistical generation information may be stored in a cache or a database ("database") associated with or embedded in the network device. The database may store the session information of each session phase.

[0028] At step 414, the hardware processor(s) 402 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 404 to calculate the difference between the sequence number of the current message or session phase in the current session and the sequence number of the previous message or previous session phase. Session information of the session phase stored in the cache or database may be analyzed or calculated to determine the difference between the sequence number of the current session phase of the session operation and the sequence number of the previous session phase of the session operation. In some examples, if the current session phase is the first session phase of the session operation, the difference will be zero (0) since there is no previous session phase. In some examples, if the difference between the sequence number of the current session phase and the sequence number of the previous session phase is greater than a preset magnitude, the current session phase is in a new session number. The new session number will be an incremented number that is one (1) more than the session number of the previous session phase. For example, if the preset magnitude is 100 and the difference between the sequence number of the current session phase and the sequence number of the previous session phase is 200, and if the previous session phase was in session number 5, then the current session phase is in session number 6. Many variations are possible. In some examples, if the difference between the sequence number of the current session phase and the sequence number of the previous session phase is less than the preset magnitude, the current session phase is in the same session number. For example, if the preset magnitude is 500 and the difference between the sequence number of the current session phase and the sequence number of the previous session phase is 499, and if the previous session phase was in session number 12, then the current session phase is in session number 12. In some examples, the first session phase of the session operation will be in session number 1. Many variations are possible.

[0029] At step 416, the hardware processor(s) 402 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 404 to determine whether the difference between the sequence numbers of the current session phase and the previous session phase is greater than a preset magnitude. In some examples, if the difference between the sequence number of the current message or session phase in the current session and the sequence number of the previous message or session phase is greater than the preset magnitude, the current session has ended and a new session is established in the client-server communication. For example, if the preset magnitude is 1000, the sequence number of the current session phase is 2227, and the sequence number of the previous session phase is 1109, then the difference in the sequence numbers is 1118, which is greater than the magnitude of 1000, so the current session has ended and a new session is being established. If the difference between the sequence number of the current message in the current session and the sequence number of the previous message is not greater than the preset magnitude, the current session continues to be active. In some examples, the preset magnitude may be a preset number. In other examples, the preset magnitude may vary periodically or based on various factors. Many variations are possible.

[0030] In some examples, when the difference between the sequence number of the current message and the sequence number of the previous message in the current session is greater than a preset margin, a timer generates an end time for the current session. The duration of the current session can be the difference between the end time and the start time of the current session. Subsequently, the hardware processor repeats the foregoing steps for each new session until the analysis for all sessions has been completed. A new session can start when a subsequent message is sent between the client device and the server in the client-server communication.

[0031] At step 422, the hardware processor(s) 402 can execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 404 to update the cache or database with session information and statistics generation information for the new session phase of the current session. In some examples, when the difference between the sequence number of the current message and the sequence number of the previous message in the current session is not greater than a preset margin, the current session continues. When a subsequent message is sent in the client-server communication, the network device can obtain session information and statistics generation information for the new message or session phase.

[0032] In response to the network device obtaining session information and statistics generation information for the new session phase of the current session, the network device can store or update the cache with the session information and statistics generation information from the new session phase of the current session.

[0033] The session operations of the client-server communication can include multiple sessions, where each session has its own statistics generation information. For example, the updated statistics generation information for the first session will include the session number, the updated sequence number of the subsequent message, the session start time, the updated session duration, the session count, the updated average duration, the updated minimum duration, the updated maximum duration, the standard deviation of the updated duration, the updated session frequency, and the session type classification based on whether the updated session duration is greater than a preset duration threshold. Each type of classification of the session can be tagged to a specific session group. The classification types can be, for example, the time of day, the device used to access the session, the application used to access the session, the duration of the session, etc. In some examples, the updated statistics generation information can be different from the previous statistics generation information. In other examples, the updated statistics generation information can be exactly the same as the previous statistics generation information. Many variations are possible.

[0034] The cache of the statistics generation information of the session operations can be read by the network device. In some examples, the network device can be a router or a switch. The network device can be monitored by an administrator. The administrator can provide feedback to the network device based on the statistics generation information stored in the cache.

[0035] Table 1 shows an example table of session detection information visible in a network device during an ongoing session operation according to various examples of the present disclosure. In Table 1, the ISN of the first session phase of the session operation is 13601. The session information of the first session phase may include the duration of the first session phase (7.744747 seconds), source information (96.43.146.176), the source port from which the messages of the first session phase are being sent (443), destination information (172.16.133.82), the destination port from which the messages of the first session phase are being sent (61228), the frame length of the session information of the first session phase (1414), the difference between the sequence number of the current session phase and the sequence number of the previous session phase (0), and the session number in which the first session phase is located (1). In Table 1, the preset amplitude is set to 10000, so that all session phases of the session operation are in session number 1 because the difference in the sequence numbers of all session phases of the session operation is lower than 10000.

[0036]

[0037] Table 1

[0038] Table 2 shows an example table of session information obtained during a session detection operation according to various examples of the present disclosure. In Table 2, session number 1 has a session start time of 10:30:00, a session duration of 30 minutes, a session count of 1, an average duration of 30, a minimum duration of 30, and a maximum duration of 30. The short - term session frequency is based on the number of short - term sessions occurring within a 30 - minute window. The short - term session frequency of session number 1 is 1. The preset duration threshold is 120 minutes, and since the session duration of session number 1 is 30 minutes which is not greater than 120 minutes, session number 1 is classified as a short - term type session. Session number 2 has a session start time of 11:45:00, a session duration of 45 minutes, a session count of 2, an average duration of 37.5, a minimum duration of 30, a maximum duration of 45, a standard deviation of the duration of 7.50, and a short - term session frequency of 0.8. Session number 2 is classified as a short - term type session because its session duration is less than the preset duration threshold of 120 minutes. The average duration, minimum duration, maximum duration, standard deviation of the duration, and short - term session frequency of session number 2 are generated based on the statistical information of the first session and the second session. The short - term type session can be one of the various classification groups of sessions.

[0039]

[0040] Table 2

[0041] Figure 5A computing component 500 is shown that includes one or more hardware processors 502 and a machine-readable storage medium 504 storing a set of machine-readable / machine-executable instructions that, when executed, cause the hardware processors 502 to perform an illustrative method of reducing computing costs while maintaining network services and performance. It should be understood that, unless otherwise stated, within the scope of the various examples described herein, additional, fewer, or alternative steps may be performed in a similar or alternative order or in parallel. The computing component 500 may be implemented as Figure 1 a router 120 or a switch 122 of Figure 2 a network device 220 of Figure 3 a computing component 300 of Figure 4 and a computing component 400 of Figure 5 summarizes and further elaborates on some of the aspects described previously.

[0042] At step 508, the hardware processors 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to obtain session information and statistical generation information for a session from a cache for a network device. In some examples, the statistical generation information for one or more sessions of a session operation may be read and obtained by the network device from the cache. In some examples, the network device may be a router or a switch. The network device may be monitored by an administrator. In some examples, the administrator may provide feedback to the network device based on the statistical generation information.

[0043] At step 510, the hardware processors 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to determine whether the session has statistical generation information with a session duration greater than a preset duration threshold. In some examples, the preset duration threshold may be a preset number. In other examples, the preset duration threshold may vary periodically or based on various factors. Many variations are possible.

[0044] At step 512, the hardware processors 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to classify the session in the cache as a long-term session type. By determining that the statistical generation information of the session includes a session duration greater than the preset duration threshold, the cache may update the statistical generation information of the session to have a classification type of a long-term session. A long-term session may be one of various session category groups.

[0045] At step 514, the hardware processor(s) 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to classify a session in the cache as a short-term session type. By determining that the statistical generation information of the session includes a session duration that is not greater than a preset duration threshold, the cache may update the statistical generation information of the session to have a classification type of a short-term session. The short-term session may be one of various session category groups.

[0046] At step 516, the hardware processor(s) 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to group together long-term session types and group together short-term session types. Once each session stored in the cache for session operations has been classified as a long-term or short-term session type based on its statistical generation information, all long-term session types are grouped together, and all short-term session types are grouped together. Long-term sessions and short-term sessions may be two of various different session category groups.

[0047] At step 518, the hardware processor(s) 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to perform load balancing on data being transmitted in the client-server communication during session operations. Once each session stored in the cache for session operations has been classified as a long-term session or a short-term session, the network device may send information about the group category to the administrator. In other examples, the administrator provides feedback to the network device to perform load balancing between sessions from two classified group types. Performing load balancing may improve the performance of transmitting information between the client device and the server and reduce the data traffic flowing between the client device and the server. Performing load balancing may prevent failures or malicious programs. Load balancing may include interleaving the transmission of frames or packets within a session such that, at any given time interval, the total traffic transmitted across all sessions is within a threshold traffic volume.

[0048] At step 520, the hardware processor(s) 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to analyze a specific session after session grouping and load balancing. The hardware processor(s) 502 may determine whether the session is a long-term session type. The network device may read and obtain the statistical generation information of the session from the cache. The statistical generation information of the session may include duration, minimum duration, maximum duration, average duration, standard deviation of duration, and type classification.

[0049] At step 522, the hardware processor(s) 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to send an alert to an administrator if a session classified as a long-term session type has a session duration that is two times (2x) greater than the average duration of the session. The network device may read and obtain the session's statistics generation information from the cache. The network device may analyze the session's statistics generation information. If the network device analyzes and determines from the statistics generation information of a session that is of the long-term session type that the session's session duration is two times (2x) greater than the average duration of the session, the network device may send an alert to the administrator. The alert may include a message notifying the administrator of a problem or risk. The administrator may provide feedback in response to the alert, where the feedback provides the network device with instructions for resolving the problem or risk. In some examples, alerting the administrator may prevent failures and malicious programs in the communication between the client device and the server.

[0050] In some examples, the statistics generation information of one or more sessions whose session operations are monitored and analyzed by the network device is analyzed. The network device may analyze the statistics generation information to determine the performance of information transmission between the client device and the server in the client-server communication. In some examples, the statistics generation information of the session duration, minimum duration, maximum duration, average duration, and standard deviation of the duration of a session of session operations is monitored and analyzed to determine if there are any problems or risks in the client-server communication. If a problem or risk is determined, the network device may send an alert to the administrator.

[0051] At step 524, the hardware processor(s) 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to send an alert to an administrator if a session classified as a short-term session type has a session duration that is two times (2x) less than the average duration of the session. The network device may read and obtain the session's statistics generation information from the cache. The network device may analyze the session's statistics generation information. If the network device analyzes and determines from the statistics generation information of a session that is of the short-term session type that the session's session duration is two times (2x) less than the average duration of the session, the network device may send an alert to the administrator. The alert may include a message notifying the administrator of a problem or risk. The administrator may provide feedback in response to the alert, where the feedback provides the network device with instructions for resolving the problem or risk. In some examples, alerting the administrator may prevent failures and malicious programs in the communication between the client device and the server.

[0052] At step 526, the hardware processor(s) 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to generate information analysis session frequencies based on statistics of multiple sessions. The network device may read and obtain the session statistics generation information from the cache. The network device may be a router or a switch. The cache for storing the statistics generation information may be associated with or embedded in the network device. The network device may monitor and analyze the session frequencies, average session frequencies, and type-classified session statistics generation information of one or more sessions of session operations. Monitoring and analyzing the statistics generation information of one or more sessions of session operations may determine the performance of transmitting information between the client device and the server. In some examples, the session frequencies, average session frequencies, and type-classified statistics generation information of one or more sessions of session operations are monitored and analyzed to determine whether an alert should be sent to the administrator.

[0053] The cache from which the network device may read the statistics generation information of session operations. In some examples, the network device may be a router or a switch. The network device may be monitored by an administrator. The administrator may provide feedback to the network device based on the statistics generation information stored in the cache. When abnormal behavior is detected, the network device may send an alert to the administrator to provide notification of the abnormal behavior. The administrator may provide feedback in response to the alert to resolve the abnormal behavior. For example, if the management module receives an alert regarding traffic data congestion in client-server communication, the management module may send feedback to the network device to perform load balancing.

[0054] At step 528, the hardware processor(s) 502 may execute machine-readable / machine-executable instructions stored in the machine-readable storage medium 504 to send an alert to the administrator if the session frequency is determined to be twice (2x) greater than the average session frequency between multiple sessions. The network device may read and obtain one or more statistics generation information of one or more sessions from the cache. The network device may analyze the multiple statistics generation information of multiple sessions with the same classification type. If the network device analyzes the statistics generation information of multiple sessions of the short-term session type and determines from the statistics generation information that the session frequency of the multiple short-term type sessions is twice (2x) greater than the average session frequency of the multiple short-term type sessions, the network device may send an alert to the administrator. If the network device analyzes the statistics generation information of multiple sessions of the long-term session type and determines from the statistics generation information that the session frequency of the multiple long-term type sessions is twice (2x) greater than the average session frequency of the multiple long-term type sessions, the network device may send an alert to the administrator.

[0055] An alert can include a message that notifies an administrator of a problem or risk. The administrator can provide feedback in response to the alert, where the feedback provides instructions to the network device for resolving the problem or risk. In some examples, alerting the administrator can prevent failures and malicious programs in the communication between the client device and the server.

[0056] Subsequently, the hardware processor can obtain subsequent entries from the cache and repeat the foregoing steps for each subsequent entry until the analysis of all entries has been completed.

[0057] Figure 6 A block diagram of an example computer system in which various examples of the present disclosure can be implemented is shown. The computer system 600 can include a bus 602 or other communication mechanism for conveying information, and one or more hardware processors 604 coupled to the bus 602 for processing information. The (multiple) hardware processors 604 can be, for example, one or more general-purpose microprocessors. The computer system 600 can be an example of a client-server communication or similar device.

[0058] The computer system 600 can also include a main memory 606, such as random access memory (RAM), cache, and / or other dynamic storage devices, coupled to the bus 602 for storing instructions and information to be executed by the (multiple) hardware processors 604. The main memory 606 can also be used to store temporary variables or other intermediate information during the execution of instructions by the (multiple) hardware processors 604. When these instructions are stored in a storage medium accessible by the (multiple) hardware processors 604, the computer system 600 becomes a special-purpose machine that can be customized to perform the operations specified in the instructions.

[0059] The computer system 600 can also include a read-only memory (ROM) 608 or other static storage device coupled to the bus 602 for storing instructions and static information for the (multiple) hardware processors 604. A storage device 610, such as a magnetic disk, optical disk, or USB thumb drive (flash drive), can be provided and coupled to the bus 602 for storing information and instructions.

[0060] The computer system 600 can also include at least one network interface 612, such as a network interface controller module (NIC), network adapter, etc., or a combination thereof, coupled to the bus 602 for connecting the computer system 600 to at least one network.

[0061] Generally, the terms "component", "module", "engine", "system", "database", etc. as used herein can refer to logic embedded in hardware or firmware, or to a collection of software instructions that may have entry and exit points and are written in a programming language such as Java, C, or C++. Software components or modules can be compiled and linked into an executable program installed in a dynamic link library, or can be written, for example, in an interpreted programming language such as BASIC, Perl, or Python. It should be understood that software components can be called from other components or from themselves, and / or can be called in response to detected events or interrupts. Software components configured to execute on a computing device such as computing system 600 can be provided on a computer-readable medium such as a compact disc, digital video disc, flash drive, magnetic disk, or any other tangible medium, or as a digital download (and can initially be stored in a compressed or installable format that requires installation, decompression, or decryption before execution). Such software code can be stored, in whole or in part, on the memory device of the executing computing device for execution by the computing device. Software instructions can be embedded in firmware such as EPROM. It should also be understood that hardware components can include connected logic units (such as gates and flip-flops), and / or can include programmable units (such as programmable gate arrays or processors).

[0062] Computer system 600 can implement the techniques or processes described herein using custom hardwired logic, one or more ASICs or FPGAs, firmware, and / or program logic combined with computer system 600 that causes or programs computer system 600 to be a special-purpose machine. According to one or more examples, the techniques described herein are performed by computer system 600 in response to one or more sequences of one or more instructions contained in main memory 606 being executed by (one or more of) hardware processors 604. Such instructions can be read into main memory 606 from another storage medium such as storage device 610. Execution of the sequence of instructions contained in main memory 606 can cause (one or more of) hardware processors 604 to perform the processing steps described herein. In alternative examples, hardwired circuitry can be used in place of or in combination with software instructions.

[0063] As used herein, the term "non-transitory medium" and like terms refer to any medium that stores instructions and / or data that cause a machine to operate in a particular manner. Such non-transitory media can include non-volatile media and / or volatile media. Non-volatile media can include, for example, optical or magnetic disks, such as storage device 610. Volatile media can include dynamic memory, such as main memory 606. Common forms of non-transitory media include, for example, floppy disks, flexible disks, hard disks, solid state drives, magnetic tape, or any other magnetic data storage media, CD-ROMs, any other optical data storage media, any physical media with hole patterns, RAMs, PROMs, and EPROMs, flash EPROMs, NVRAMs, any other memory chip or cartridge, and networked versions thereof.

[0064] Non-transitory media are different from transmission media but can be used in conjunction with transmission media. Transmission media can participate in transferring information between non-transitory media. For example, transmission media can include coaxial cables, copper wire, and optical fibers, which include the wires that form bus 402. Transmission media can also take the form of acoustic or light waves, such as waves generated during radio wave and infrared data communications.

[0065] As used herein, the term "or" can be interpreted in an inclusive or exclusive sense. Further, descriptions of resources, operations, or structures in the singular form should not be construed as excluding plural instances. Unless expressly stated otherwise or otherwise understood in the context in which it is used, conditional language such as, in particular, "can," "could," "might," or "may" is generally intended to convey that a particular example includes (while other examples do not include) a particular feature, element, and / or step.

[0066] Unless expressly stated otherwise, the terms and phrases used in this document and their variants should be construed as open-ended rather than limiting. Adjectives such as "conventional," "traditional," "normal," "standard," "known," and terms of similar import should not be construed as limiting the thing described to that available or known at a given time period or given time, but rather should be understood to encompass conventional, traditional, normal, or standard techniques that are available or known at any time, present or future. In some instances, the presence of broad words and phrases such as "one or more," "at least," "but not limited to," or other similar phrases should not be construed to imply that a narrower situation is intended or required where such broad phrases might not be present.

Claims

1. A computing system, comprising a network, network devices, clients, and a server, wherein the network devices include one or more processors; and a memory storing instructions that, when executed by the one or more processors, cause the one or more processors to: Receive session information associated with a session; Record the session information; Determine the type of the session, wherein: If the session duration is greater than a duration threshold, the type of the session is long-term; or The type of the session is short-term; Classify the session into a session group of a plurality of session groups based on the session information; Analyze the session information based on the classified session group of the session; Determine the frequency of short-term sessions within a set time period; Determine the frequency of long-term sessions within a set time period; Determine an average frequency based on the frequency of the short-term sessions and the frequency of the long-term sessions; Determine abnormal behavior between the sessions in the session group; And Send an alert for the determined abnormal behavior; Perform load balancing on the session based on the analysis and classification of the session, wherein the load balancing includes interleaving the transmission of frames or packets within the session such that, at any given time interval, the total traffic transmitted across all the sessions is within a threshold traffic volume.

2. The computing system according to claim 1, wherein the session information includes the source IP, destination IP, source port, destination port, session start time, session duration, session count, and frame length of the session information.

3. The computing system according to claim 1, further comprising: Sorting the short-term sessions and the long-term sessions for load balancing.

4. The computing system according to claim 1, wherein the determining of the abnormal behavior between the sessions in the session group further includes: Determining that the frequency of the short-term sessions is at least twice greater than the average frequency; And Determining that the frequency of the long-term sessions is at least twice less than the average frequency.

5. The computing system according to claim 1, wherein the analyzing of the session information further includes: Comparing the session information of multiple sessions in the classified session group; Determining abnormal behavior between the sessions in the classified session group based on the compared session information; And Sending an alert for the determined abnormal behavior.

Citation Information

Patent Citations

  • Method, node manager and system for load balancing in cloud computing system

    CN102624916A

  • Method and device for transmitting multiple video streams

    CN105830445A