Network analysis system and network analysis method
Patent Information
- Application Number
- CN202310232682.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-03
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2043-03-03
AI Technical Summary
然而,上述方法精准捕获数据包难,对内存和磁盘占用大,此外,由于数据包错综复杂,人工分析势必会引入大量不确定因素,导致分析结果不准确,网络性能刻画难
[0012] This specification provides a network analysis system according to one embodiment, including a server and a network interface card (NIC). The NIC is configured to transmit data streams. The server is configured to obtain data packets from the data stream using the NIC. Based on a layered network protocol, the system obtains content corresponding to multiple network layers of the data packets. Using this content, the system analyzes the characteristics of the data stream at each network layer. Finally, it generates performance metrics for the data stream based on these characteristics. By obtaining the content corresponding to multiple network layers of the data packets according to the layered network protocol, and further utilizing this content to determine the characteristics of the data stream at each network layer, the server automatically and accurately analyzes the characteristics of the data stream in each network layer, efficiently and accurately determining the performance metrics of the data stream, thereby quickly identifying network bottlenecks.
Smart Images

Figure CN116366483B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology, and in particular to a network analysis system. One or more embodiments of this specification also relate to a network analysis method, a computing device, a computer-readable storage medium, and a computer program. Background Technology
[0002] With the development of computer technology, the amount of data generated by enterprises or individual users has exploded, and the requirements for network transmission have also increased. Therefore, how to accurately find network bottlenecks and quickly locate network problems in highly complex systems has gradually become a research focus.
[0003] Currently, packet capture tools are typically used to acquire network packets, which are then manually analyzed to determine if network bottlenecks exist. However, this method is difficult to accurately capture packets, consumes significant amounts of memory and disk space, and the complexity of data packets inevitably introduces numerous uncertainties into manual analysis, leading to inaccurate results and difficulty in characterizing network performance. Therefore, an efficient and accurate network analysis solution is urgently needed. Summary of the Invention
[0004] In view of this, embodiments of this specification provide a network analysis system. One or more embodiments of this specification also relate to a network analysis method, a computing device, a computer-readable storage medium, and a computer program, to address the technical deficiencies existing in the prior art.
[0005] According to a first aspect of the embodiments of this specification, a network analysis system is provided, including: a server and a network interface card (NIC); the NIC is configured to transmit a data stream; the server is configured to obtain data packets from the data stream from the NIC; obtain content corresponding to multiple network layers of the data packets according to a layered network protocol; analyze the characteristics of the data stream at each network layer using the content corresponding to the multiple network layers of the data packets; and generate performance indicators of the data stream using the characteristics of the data stream at each network layer.
[0006] According to a second aspect of the embodiments of this specification, a network analysis method is provided, comprising: acquiring data packets in a data stream; obtaining content corresponding to multiple network layers of the data packets according to a layered network protocol; analyzing the characteristics of the data stream at each network layer using the content corresponding to the multiple network layers of the data packets; and generating performance indicators of the data stream using the characteristics of the data stream at each network layer.
[0007] According to a third aspect of the embodiments of this specification, a network analysis apparatus is provided, comprising: an acquisition module configured to acquire data packets in a data stream; a layering module configured to obtain content corresponding to multiple network layers of the data packets according to a layered network protocol; an analysis module configured to analyze the characteristics of the data stream at each network layer using the content corresponding to the multiple network layers of the data packets; and a generation module configured to generate performance indicators of the data stream using the characteristics of the data stream at each network layer.
[0008] According to a fourth aspect of the embodiments of this specification, a computing device is provided, comprising:
[0009] A memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the above-described network analysis method.
[0010] According to a fifth aspect of the embodiments of this specification, a computer-readable storage medium is provided that stores computer-executable instructions that, when executed by a processor, implement the steps of the network analysis method described above.
[0011] According to a sixth aspect of the embodiments of this specification, a computer program is provided, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the network analysis method described above.
[0012] This specification provides a network analysis system according to one embodiment, including a server and a network interface card (NIC). The NIC is configured to transmit data streams. The server is configured to obtain data packets from the data stream using the NIC. Based on a layered network protocol, the system obtains content corresponding to multiple network layers of the data packets. Using this content, the system analyzes the characteristics of the data stream at each network layer. Finally, it generates performance metrics for the data stream based on these characteristics. By obtaining the content corresponding to multiple network layers of the data packets according to the layered network protocol, and further utilizing this content to determine the characteristics of the data stream at each network layer, the server automatically and accurately analyzes the characteristics of the data stream in each network layer, efficiently and accurately determining the performance metrics of the data stream, thereby quickly identifying network bottlenecks. Attached Figure Description
[0013] Figure 1 This is an architecture diagram of a network analysis system provided in one embodiment of this specification;
[0014] Figure 2 This is a framework diagram of another network analysis system provided in one embodiment of this specification;
[0015] Figure 3This is a flowchart illustrating a network analysis method provided in one embodiment of this specification;
[0016] Figure 4 This is a schematic diagram of the storage structure in a network analysis method provided in one embodiment of this specification;
[0017] Figure 5 This is a schematic diagram of a general interface in a network analysis method provided in one embodiment of this specification;
[0018] Figure 6 This is a flowchart illustrating the processing procedure of a network analysis method provided in one embodiment of this specification;
[0019] Figure 7 This is a flowchart illustrating the processing of a traffic capture component in a network analysis system according to one embodiment of this specification.
[0020] Figure 8 This is a flowchart illustrating the processing of a performance analysis component in a network analysis system, as provided in one embodiment of this specification.
[0021] Figure 9 This is a schematic diagram of the structure of a network analysis device provided in one embodiment of this specification;
[0022] Figure 10 This is a structural block diagram of a computing device provided in one embodiment of this specification. Detailed Implementation
[0023] Many specific details are set forth in the following description to provide a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.
[0024] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this specification. The singular forms “a,” “described,” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0025] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."
[0026] First, the terms and concepts used in one or more embodiments of this specification will be explained.
[0027] Data packets, also known as packets, are formed in packet-switched networks by dividing a single message into multiple data blocks called packets. These packets contain at least the address information of the sender and receiver. They are transmitted through the network and reassembled into a message at their destination.
[0028] Data stream: A data stream is an ordered sequence of bytes with a start and an end, including input streams and output streams.
[0029] Edge computing: Edge computing provides edge intelligence services at the network edge, close to the source of objects or data, by integrating core capabilities of network, computing, storage, and application through a distributed open platform.
[0030] Network protocols: Network protocols refer to the rules that computers on the same network must follow when connecting and communicating. In computer networks, the rules for connection and communication are called network protocols, also known as network communication protocols. They provide unified specifications for data transmission formats, transmission rates, transmission steps, etc., and both communicating parties must adhere to them to complete data exchange.
[0031] Transmission Control Protocol (TCP): TCP is a connection-oriented, reliable, byte-stream-based transport layer communication protocol. TCP is designed to adapt to layered protocol hierarchies that support multiple network applications.
[0032] Hypertext Transfer Protocol: The Hypertext Transfer Protocol (HTTP) is a simple request-response protocol that typically runs on top of the Transmission Control Protocol.
[0033] User Datagram Protocol (UDP): The User Datagram Protocol (UDP) is a connectionless transport layer protocol in the Open Systems Internet Communication Reference Model, providing a simple, unreliable, transaction-oriented message delivery service.
[0034] Network Address Protocol (NIC): Also known as the Internet Protocol (IP), the IP protocol is a protocol designed for communication between interconnected computer networks. In the Internet, it is a set of rules that enables all computer networks connected to the network to communicate with each other, specifying the rules that computers must follow when communicating on the Internet.
[0035] Transport Layer Security (TLS): The Transport Layer Security protocol is used to provide confidentiality and data integrity between two communicating applications.
[0036] Multiple Access Control Protocol (MAC): The Multiple Access Control Protocol uses a distributed algorithm to determine how nodes share the channel, that is, when a node can transmit data.
[0037] Regular expressions: Regular expressions describe a pattern for matching strings. They can be used to check if a string contains a certain substring, replace matched substrings, or extract substrings from a string that meet certain conditions.
[0038] Request-level analysis: Request-level analysis refers to breaking down the data packets of each request from a large amount of traffic, analyzing the overall system performance by taking a single request as the unit.
[0039] User mode: When a process is executing its own user code, it is said to be in user running mode.
[0040] Kernel mode: When a task (process) executes a system call and gets trapped in kernel code, the process is said to be in kernel running mode.
[0041] With the rapid development of the internet, the amount of data generated by enterprises and individual users is exploding, and the market size of edge computing is also growing larger. The network is the foundation of edge computing, and the improvement of product performance is inseparable from the optimization of the network. How to accurately find network bottlenecks and quickly locate network problems in highly complex systems has gradually become a research focus.
[0042] Currently, users typically capture data packets using custom filtering rules in packet capture tools, and then manually analyze these packets to determine if there are bottlenecks in the network. However, this method inevitably introduces many uncertainties, leading to inaccurate analysis results and difficulty in characterizing network performance. Furthermore, captured data packets consume significant memory and disk space, and due to their complexity, it's difficult to flexibly capture traffic carrying specific content at the application layer, lacking automated network analysis capabilities. Therefore, there is an urgent need for an efficient and accurate network analysis solution.
[0043] To address the aforementioned issues, this specification provides an efficient and accurate network analysis system that resolves the pain points of high memory and disk usage for capturing traffic in high-traffic scenarios, difficulty in accurately capturing target traffic, and difficulty in characterizing network performance due to complex data packets. It can quickly analyze network problems, improve efficiency, and enhance the overall quality of edge computing products.
[0044] Specifically, the network analysis system includes a server and a network interface card (NIC). The NIC is configured to transmit data streams. The server is configured to retrieve data packets from the NIC. Based on a layered network protocol, it obtains the content corresponding to multiple network layers of the data packets. Using this content, it analyzes the characteristics of the data stream at each network layer. Finally, it generates performance metrics for the data stream based on these characteristics. By obtaining the content corresponding to multiple network layers of the data packets according to the layered network protocol, and further utilizing this content to determine the characteristics of the data stream at each network layer, the server automatically and accurately analyzes the characteristics of the data stream at each network layer, efficiently and accurately determining the performance metrics of the data stream, thereby quickly identifying network bottlenecks.
[0045] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in the embodiments of this specification are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0046] This specification provides a network analysis system, a network analysis method, a computing device, a computer-readable storage medium, and a computer program, which are described in detail in the following embodiments.
[0047] See Figure 1 , Figure 1This specification shows an architecture diagram of a network analysis system provided in one embodiment. The network analysis system includes: a server and a network interface card (NIC).
[0048] The network interface card (NIC) is configured to transmit data streams;
[0049] The server is configured to retrieve data packets from the network interface card (NIC); obtain the content corresponding to multiple network layers of the data packets according to the layered network protocol; analyze the characteristics of the data stream at each network layer using the content corresponding to the multiple network layers of the data packets; and generate performance metrics of the data stream using the characteristics of the data stream at each network layer.
[0050] Furthermore, the server-side component can include two parts: a traffic capture component and a performance analysis component. The traffic capture component is used to obtain data packets from the network interface card (NIC). The performance analysis component is used to obtain the content corresponding to multiple network layers of the data packets according to the layered network protocol; using this content, it analyzes the characteristics of the data stream at each network layer; and using these characteristics, it generates performance metrics for the data stream.
[0051] Applying the scheme of the embodiments in this specification, the server obtains data packets from the data stream from the network interface card (NIC); according to the layered network protocol, it obtains the content corresponding to multiple network layers of the data packets; using the content corresponding to the multiple network layers of the data packets, it analyzes the characteristics of the data stream at each network layer; and using the characteristics of the data stream at each network layer, it generates performance indicators for the data stream. By obtaining the content corresponding to multiple network layers of the data packets according to the layered network protocol, and further using the content corresponding to multiple network layers to determine the characteristics of the data stream at each network layer, the server achieves automatic and accurate analysis of the characteristics of the data stream in each network layer, efficiently and accurately determines the performance indicators of the data stream, and thus quickly identifies network bottlenecks.
[0052] See Figure 2 , Figure 2 This specification illustrates a framework diagram of another network analysis system provided in one embodiment. The system may include a server 100 and multiple clients 200. The multiple clients 200 can establish communication connections through the server 100. In a network analysis scenario, the server 100 is used to provide network analysis services between the multiple clients 200. The multiple clients 200 can act as either senders or receivers, communicating through the server 100.
[0053] Users can interact with server 100 through client 200 to receive data sent by other clients 200, or send data to other clients 200, etc. In a network analysis scenario, a user can publish a network analysis request to server 100 through client 200, server 100 can generate network analysis results based on the network analysis request, and push the network analysis results to other clients 200 that have established communication.
[0054] In this system, client 200 and server 100 establish a connection via a network. The network provides the medium for communication between client 200 and server 100. The network can include various connection types, such as wired or wireless communication links or fiber optic cables. Data transmitted by client 200 may need to undergo encoding, transcoding, compression, or other processing before being published to server 100.
[0055] Client 200 can be a browser, an app (application), a web application such as an H5 (HyperText Markup Language 5) application, a lightweight application (also known as a mini-program), or a cloud application. Client 200 can be developed based on the software development kit (SDK) provided by the server, such as a real-time communication (RTC) SDK. Client 200 can be deployed on electronic devices, requiring the device to run or certain apps on the device to function. Electronic devices may have displays and support information browsing, such as personal mobile terminals like smartphones, tablets, and personal computers. Various other types of applications can also be configured on electronic devices, such as human-computer interaction applications, model training applications, text processing applications, web browser applications, shopping applications, search applications, instant messaging tools, email clients, and social media platforms.
[0056] Server 100 may include servers providing various services, such as servers providing communication services to multiple clients, servers supporting backend training of models used on clients, and servers processing data sent by clients. It should be noted that server 100 can be implemented as a distributed server cluster composed of multiple servers, or as a single server. The server can also be a server in a distributed system, or a server integrated with blockchain. The server can also be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms, or an intelligent cloud computing server or intelligent cloud host with artificial intelligence technology.
[0057] It is worth noting that the network analysis method provided in the embodiments of this specification is generally executed by the server 100. However, in other embodiments of this specification, the client 200 may also have similar functions to the server, thereby executing the network analysis method provided in the embodiments of this specification. In other embodiments, the network analysis method provided in the embodiments of this specification may also be executed jointly by the client 200 and the server 100.
[0058] See Figure 3 , Figure 3 This specification shows a flowchart of a network analysis method provided in one embodiment, which specifically includes the following steps:
[0059] Step 302: Obtain data packets from the data stream.
[0060] In one or more embodiments of this specification, during network analysis, data packets in a data stream can be acquired, thereby enabling network analysis using the data packets in the data stream.
[0061] Specifically, a data stream is a link of Network Address Protocol (NAT) or Transmission Control Protocol (TCP) data, which contains multiple data packets. The payload of these data packets is the data remaining after removing all protocol headers, used to describe a complete action (data exchanged between the server and the client).
[0062] In practical applications, there are various ways to acquire data packets from a data stream, and the specific method chosen depends on the actual situation. This specification does not impose any limitations on these methods in its embodiments. One possible implementation of this specification involves actively acquiring data packets from the data stream. Another possible implementation involves receiving a network analysis request sent by a user and, in response to the request, acquiring data packets from the data stream. Furthermore, when acquiring data packets from the data stream, network data packets can be captured directly using a data table capture tool, or they can be acquired through a relevant data packet capture application programming interface (API).
[0063] It should be noted that after acquiring data packets from the data stream, the acquired data packets can be directly used as data packets to be analyzed, and their contents can be processed. Alternatively, data packets in the data stream can be filtered to obtain data packets to be analyzed, thereby reducing the number of data packets, further reducing the amount of data processing, and improving network analysis efficiency.
[0064] Step 304: Obtain the content corresponding to multiple network layers of the data packet according to the layered network protocol.
[0065] Specifically, layered network protocols are a type of computer network architecture that uses a hierarchical approach to divide the necessary functions of a communication protocol into layers. Each layer receives specific services from the layer below it and is responsible for providing specific services to the layer above it.
[0066] It should be noted that network layering methods include, but are not limited to, using the Open Systems Interconnection Reference Model (OSI) seven-layer model, the Transmission Control Protocol (TCP) four-layer model, and the Network Address Protocol (NAT) four-layer model. In practical applications, a specific network layer can be selected from the aforementioned four-layer and seven-layer models for network analysis based on the specific project requirements. Taking the OSI seven-layer model as an example, the resulting network layers include the physical layer, data link layer, network layer, transport layer, session layer, presentation layer, and application layer. Specifically:
[0067] Application Layer: Provides various request services for applications or user requests. It is the highest layer in the Open Systems Internet Communication (OSI) seven-layer model and the layer closest to the user. It provides interfaces for computer users, various applications, and the network, and also directly provides various network services to users.
[0068] Presentation Layer: Data encoding, format conversion, and data encryption. It provides various encoding and conversion functions for application layer data, ensuring that data sent by the application layer of one system can be recognized by the application layer of another system. If necessary, this layer can provide a standard representation to convert various internal computer data formats into the standard representation used in communication. Data compression and encryption are also among the conversion functions provided by the presentation layer.
[0069] Session Layer: Creates, manages, and maintains sessions. It receives data from the transport layer and is responsible for establishing, managing, and terminating communication sessions between presentation layer entities, supporting data exchange between them. Communication at this layer consists of service requests and responses between applications on different devices.
[0070] Transport Layer: Data Communication. Establishes end-to-end links between hosts, providing reliable and transparent data transmission services to the session and network layers, ensuring that data is transmitted intact to the network layer.
[0071] Network Layer: Network address protocol addressing and routing. It selects the most appropriate path for messages or communication subnets using routing algorithms. It controls information forwarding between the data link layer and the transport layer, establishing, maintaining, and terminating network connections. Data at the data link layer is converted into data packets at this layer, and then, through path selection, segmentation and reassembly, sequencing, and inbound / outbound routing, information is transmitted from one network device to another.
[0072] Data Link Layer: Provides media access and link management. It receives data from the physical layer in bit stream form, encapsulates it into frames, and transmits them to the network layer; it also decapsulates and reassembles data frames from the network layer into bit stream form and forwards them to the physical layer; it is responsible for establishing and managing links between nodes, and through various control protocols, transforms error-prone physical channels into error-free data links capable of reliably transmitting data frames.
[0073] Physical Layer: Manages the interconnection between communication devices and network media. The transmission medium provides the physical connection for the data link layer, enabling transparent transmission of bit streams. It enables transparent transmission of bit streams between adjacent computer nodes, shielding the differences in specific transmission media and physical devices.
[0074] Step 306: Analyze the characteristics of the data flow at each network layer by utilizing the content corresponding to the multiple network layers of the data packet.
[0075] In one or more embodiments of this specification, after obtaining data packets in a data stream and acquiring the content corresponding to multiple network layers of the data packets according to a layered network protocol, the characteristics of the data stream at each network layer can be analyzed using the content corresponding to the multiple network layers of the data packets.
[0076] Specifically, the characteristics of a data stream refer to the performance information of the data stream at each network layer, including but not limited to the first packet time, the time taken during the Transmission Control Protocol handshake phase, the time taken during the Secure Socket Layer (SSL) handshake phase, the time taken for the remaining packets to be transmitted, etc. The specific selection is based on the actual situation, and the embodiments in this specification do not impose any limitations on this.
[0077] It should be noted that when analyzing the characteristics of data flows at each network layer using the content corresponding to multiple network layers of data packets, the analysis methods differ for each network layer. The specific method should be selected based on the actual situation, and this specification does not impose any limitations on this. For example, at the data link layer, the hardware addresses at both ends of the data packet can be determined, and the data packets can be streamed using these addresses to identify data packets belonging to the same data flow. Similarly, at the network layer, the network address of the data packet can be determined, and the data packets can be streamed using these addresses to identify data packets belonging to the same data flow. Furthermore, after determining the data flows in different network layers, the network characteristics of the data flows can be determined on a per-data-flow basis.
[0078] Step 308: Generate performance metrics for the data stream using the characteristics of the data stream at each network layer.
[0079] In one or more embodiments of this specification, data packets in a data stream are acquired, and according to a layered network protocol, the content corresponding to multiple network layers of the data packets is obtained. After analyzing the characteristics of the data stream at each network layer using the content corresponding to the multiple network layers of the data packets, the performance indicators of the data stream can be generated using the characteristics of the data stream at each network layer.
[0080] Specifically, the performance metrics of the data stream are used to evaluate the network performance of the data stream, including but not limited to network conditions and specific quantitative indicators such as transmission speed and transmission time. The specific selection is based on the actual situation, and the embodiments in this specification do not impose any limitations on this.
[0081] In practical applications, there are various ways to generate data stream performance metrics based on the characteristics of the data stream at each network layer. The specific method chosen depends on the actual situation, and this specification does not impose any limitations on this approach. One possible implementation of this specification is to directly generate data stream performance metrics based on the characteristics of the data stream at each network layer. For example, if the retransmission rate is greater than a preset retransmission threshold, the data stream performance metric is directly determined to be "poor transmission performance." Another possible implementation of this specification involves, after obtaining the characteristics of the data stream at each network layer, quantizing the characteristics of the data stream corresponding to the network analysis request at each layer within multiple preset segments of the network analysis request's lifecycle, thereby obtaining quantization results corresponding to multiple preset segments.
[0082] The scheme described in this specification involves acquiring data packets from a data stream; obtaining the content corresponding to multiple network layers of the data packets according to a layered network protocol; analyzing the characteristics of the data stream at each network layer using the content corresponding to the multiple network layers of the data packets; and generating performance indicators for the data stream using the characteristics of the data stream at each network layer. By obtaining the content corresponding to multiple network layers of the data packets according to the layered network protocol, and further using the content corresponding to multiple network layers to determine the characteristics of the data stream at each network layer, the system achieves automatic and accurate analysis of the characteristics of the data stream in each network layer, efficiently and accurately determining the performance indicators of the data stream, thereby quickly identifying network bottlenecks.
[0083] In a first optional embodiment of this specification, preset data packet filtering conditions can be used to filter data packets in the data stream to obtain the data packets to be analyzed. That is, the above-mentioned acquisition of data packets in the data stream may include the following steps:
[0084] At the data link layer, preset data packet filtering conditions are used to filter data packets in the data stream passing through the data link layer to obtain the data packets to be analyzed.
[0085] Specifically, the preset data packet filtering conditions include, but are not limited to, general packet filters (BPF, Berkeley Packet Filter), display filters, etc., and should be selected according to the actual situation. This specification does not limit them in any way.
[0086] It's important to note that the data packet flow process is as follows: transmission through network cable / fiber optic cable devices, reaching the host network interface card (NIC), then to the device driver layer, data link layer, IP layer, transport layer, and finally, the data is used by the application. When capturing data packets from the data stream, taking packet capture as an example, a bypass process is added at the data link layer. A corresponding application programming interface (API) is encapsulated for developers, allowing them to capture data packets flowing through the NIC. Furthermore, after capturing the data packets flowing through the NIC, all data packets can be filtered according to user-defined packet filtering conditions, ultimately retaining only those that meet the preset filtering criteria for analysis.
[0087] By applying the scheme of the embodiments in this specification, at the data link layer, preset data packet filtering conditions are used to filter the data packets in the data stream passing through the data link layer to obtain the data packets to be analyzed, thereby reducing the number of data packets, thus reducing the amount of network analysis data, and further improving the efficiency of network analysis.
[0088] In a second optional embodiment of this specification, deep packet inspection (DPI) technology can be used to filter data packets based on the content of the application layer to obtain the data packets to be analyzed. That is, the above-mentioned acquisition of data packets in the data stream may include the following steps:
[0089] Identify the content of the data packets to be analyzed in the data stream and determine the application layer content in the data packets;
[0090] The application layer content is matched according to preset matching conditions, and data packets that meet the preset matching conditions are used as updated data packets to be analyzed.
[0091] Specifically, the preset matching conditions include, but are not limited to, specifying a domain name, specifying a Uniform Resource Locator (URL), and specifying a Hypertext Transfer Protocol header value. The specific selection is made according to the actual situation, and the embodiments in this specification do not impose any limitations on this.
[0092] It should be noted that there are multiple ways to identify the content of the data packets to be analyzed in the data stream and determine the application layer content within the data packets. The specific method should be selected according to the actual situation, and the embodiments in this specification do not impose any limitations on this. In one possible implementation of this specification, the content of the data packets carries network layer tags, and the network layer tags carried by each content can be directly identified to determine the application layer content. In another possible implementation of this specification, a pre-trained network layer recognition model can be used to identify the content of the data packets to be analyzed, thereby determining the application layer content within the data packets.
[0093] Furthermore, after determining the application layer content in the data packet, the application layer content can be directly matched using preset matching conditions, or regular expressions can be used to perform regular expression matching on the application layer content to obtain the data packet to be analyzed.
[0094] For example, the payload of each data packet can be extracted, and client / server processing can be supported separately at the transmission control protocol level. For example, " / success / s&&! / fail / c" is intended to obtain the data stream from the server application layer that contains "success" but not "fail". When obtaining traffic with a specified domain name, a specified Uniform Resource Locator, or a specified Hypertext Transfer Protocol header value, the corresponding expression is generated.
[0095] The scheme described in this specification identifies the content of data packets to be analyzed in a data stream, determining the application layer content within the data packets. The application layer content is then matched against preset matching conditions, and data packets meeting these conditions are selected as updated data packets to be analyzed. This more flexible matching function enables data packet filtering, reducing the number of data packets and consequently the amount of network analysis data, further improving network analysis efficiency.
[0096] In the third optional embodiment of this specification, filtering with other additional conditions is supported, including slow stream filtering, retransmission rate filtering, transmission size filtering, etc. That is, the above-mentioned acquisition of data packets in the data stream may include the following steps:
[0097] Calculate the transmission parameters of the data packets to be analyzed in the data stream, wherein the transmission parameters include at least one of transmission speed, retransmission index and transmission size;
[0098] Using preset transmission parameter conditions and the transmission parameters of the data packets to be analyzed, data packets that meet the preset transmission parameter conditions are used as updated data packets to be analyzed.
[0099] Specifically, the client-side zero-window time is the time during which the client's sliding window is zero. When the client's sliding window is zero, the server will stop sending. An excessively long client-side zero-window time will affect the accuracy of the server's performance evaluation. Preset transmission parameters include, but are not limited to, transmission speed thresholds, retransmission count thresholds, retransmission rate thresholds, and transmission size thresholds.
[0100] In practical applications, the data packet transmission speed can be calculated using the following formula (1), the zero-window removal speed can be calculated using the following formula (2), the retransmission rate can be calculated using the following formula (3), the network condition can be judged using the retransmission rate, and the transmission size can be calculated using the following formula (4):
[0101] s1=∑len(tcp_payload) / t (1)
[0102] s2=∑len(tcp_payload) / t-t1 (2)
[0103] r = ∑len(retransmission tcp_payload) / ∑len(tcp_payload) - ∑len(retransmission tcp_payload) (3)
[0104] L=Σlen(tcp_payload) (4)
[0105] Where s1 is the data packet transmission rate, s2 is the zero-window removal rate, r is the retransmission rate, L is the transmission size, t is the transmission time, t1 is the sum of the time when the packet window of all clients is 0, and tcp_payload is the transmission control protocol payload.
[0106] The scheme described in this specification calculates the transmission parameters of the data packets to be analyzed in the data stream. These transmission parameters include at least one of transmission speed, retransmission rate, and transmission size. Using preset transmission parameter conditions and the transmission parameters of the data packets to be analyzed, data packets that meet the preset transmission parameter conditions are used as updated data packets to be analyzed. By judging transmission parameters such as download speed, retransmission rate, and transmission size at the request level, traffic that does not meet the preset transmission parameter conditions is filtered out, thereby reducing the number of data packets, reducing the amount of network analysis data, and further improving network analysis efficiency. Furthermore, when calculating slow flows, the client's zero-window time can be removed, better reflecting the server's network status.
[0107] In one optional embodiment of this specification, in order to reduce the occupation of host resources and protect the host, after acquiring the data packets in the data stream, the following steps may be included:
[0108] Store the data packet to persistent storage and delete the data packet from memory.
[0109] Specifically, persistent storage refers to saving data to a storage device that can be permanently stored (such as a disk, cloud storage components, etc.). Persistence is a mechanism for converting program data between a persistent state and a transient state. In the embodiments of this specification, the method of storing data packets to persistent storage and deleting data packets from memory can be called timed disk persistence.
[0110] Furthermore, in the embodiments of this specification, when performing network analysis, a security model can be used to calculate the consumption of host resources in real time. When the consumption value exceeds the security threshold, the network analysis is actively terminated.
[0111] The solution described in this specification involves storing data packets in persistent storage and deleting them from memory. Data in memory can be promptly transferred to the hard drive for persistent storage, and then the memory can be released in a timely manner to prevent the continuous increase in memory usage from affecting other service processes. Finally, the hard drive space is released, and the data is transferred to the cloud for persistent storage.
[0112] In one optional embodiment of this specification, the multiple network layers include a data link layer; the above-described analysis of the characteristics of the data flow at each network layer using the content corresponding to the multiple network layers of the data packets may include the following steps:
[0113] The data link layer content in the data packet is analyzed according to the multiple access control protocol to determine the hardware addresses at both ends of the data packet.
[0114] Using dual-end hardware addresses to identify data packets belonging to the same data stream;
[0115] Analyze the network interface card information corresponding to the data stream based on the hardware addresses at both ends of the data packet.
[0116] Specifically, when streaming data packets in the data link layer (MAC Flow), it supports the splitting of MAC (Media Access Control) data streams and the traffic statistics function of the network interface card, and supports data link layer feature analysis. Streaming refers to classifying all data packets and placing data packets belonging to the corresponding stream in the same structure.
[0117] In practical applications, by analyzing the data link layer content of data packets according to the multiple access control protocol, the determined end-to-end hardware addresses include the sender and receiver. For example, data packets "A to B" and "A to C" belong to different data streams. The traffic statistics function is a summary function that can calculate all captured data packets. Data link layer feature analysis mainly determines whether it is a physical network interface card (NIC) or a virtual NIC by analyzing the first 8 bytes of the end-to-end hardware addresses.
[0118] The scheme described in this specification analyzes the data link layer content of data packets according to the multiple access control protocol to determine the dual-end hardware addresses of the data packets; it uses the dual-end hardware addresses to identify data packets belonging to the same data stream; and it analyzes the network interface card (NIC) information corresponding to the data stream based on the dual-end hardware addresses of the data packets. This achieves accurate determination of NIC information for data streams on a per-data-stream basis, further enabling efficient and accurate determination of data stream performance metrics.
[0119] In one optional embodiment of this specification, the multiple network layers include network layers; the above-described analysis of the characteristics of the data flow at each network layer using the content corresponding to the multiple network layers of the data packets may include at least one of the following steps:
[0120] The network address of a data packet is determined by analyzing the network layer content in the data packet according to the network address protocol, and the network address is used to identify data packets belonging to the same data stream.
[0121] The location of the captured data packet can be determined by using the Time-to-Live (TTL) value recorded at the network layer in the data packet.
[0122] The version information of the network address protocol is determined based on the header value of the network address protocol.
[0123] Specifically, when streaming data packets at the network layer (IPFlow), the data packets can be identified by their network addresses, and the system also supports functions such as data stream splitting, network address protocol version determination, and packet capture location determination.
[0124] In practical applications, after analyzing the network layer content of data packets according to the Network Address Protocol (NAT) to determine the network address of the data packets, the network addresses at both ends can be used to identify data packets belonging to the same data stream. Since the Time To Live (TTL) value of the packet capture location is usually an integer multiple of 64, the packet capture location can be determined by analyzing the NAT TTL value.
[0125] The scheme implemented in this specification analyzes the network layer content of data packets according to the Network Address Protocol (NAT) to determine the network address of the data packets and uses the network address to identify data packets belonging to the same data stream. The packet capture location is determined using the Time-to-Live (TTL) value recorded in the network layer of the data packets. The NAT version information is determined based on the NAT header value. This achieves accurate determination of the packet capture location and NAT version information of a data stream, further enabling efficient and accurate determination of data stream performance metrics.
[0126] In one optional embodiment of this specification, the multiple network layers include a transport layer; the above-described analysis of the characteristics of the data stream at each network layer using the content corresponding to the multiple network layers of the data packet may include at least one of the following steps:
[0127] The content corresponding to the transport layer in the data packet is analyzed according to the transmission protocol to determine the port information of the data packet, and the port information is used to identify data packets belonging to the same data stream.
[0128] Based on the request information in the data packet, determine the connection information corresponding to the data packet;
[0129] Based on the disconnection behavior in the transport layer, determine the disconnection information corresponding to the data packet.
[0130] Specifically, when streaming data packets at the transport layer (TCP, UDP Flow), it supports Transmission Control Protocol (TCP) and User Datagram Protocol (UDP), using network address and port as unique identifiers for the data stream. Taking TCP as an example, it supports TCP connection establishment handshake analysis, TCP connection termination analysis, zero window analysis, retransmission rate analysis, and TCP header value analysis.
[0131] In practical applications, the Transmission Control Protocol (TCP) connection establishment time can be calculated using the following formula (5):
[0132] T1 = t1(c_ack) - t2(c_syn) (5)
[0133] Where t1(c_ack) represents the moment when the client sends the connection establishment response acknowledgment (ack) packet, and t2(c_syn) represents the moment when the client sends the connection establishment request (syn) synchronous packet.
[0134] When analyzing the disconnection of the Transmission Control Protocol (TCP), there are multiple ways to disconnect. The specific disconnection behavior can be determined by the characteristics of the packet. For example, if the reset (RST) flag is captured, it is a forced disconnection due to reset. If the complete behavior of closing the connection (FIN) and closing the connection-response (FIN_ACK) is captured, it is a normal "four-way handshake" negotiated disconnection.
[0135] In zero-window analysis, when the data sent by the sender exceeds the upper limit of the receiver's window, the receiver will exhibit a zero-window phenomenon. By capturing the zero window, when the download speed is lower than expected, the extent to which it is affected by the client's processing capacity can be determined.
[0136] When analyzing the Transmission Control Protocol (TCP) header, it's important to understand that the header contains a wealth of information, including port, sequence number, acknowledgment number, window, and options. Therefore, analyzing the TCP header can reveal behaviors such as window size changes and SACK (Selective Acknowledgment) behavior. SACK is a TCP option that allows the TCP to individually acknowledge discontinuous segments, informing the recipient of truly lost packets and retransmitting only the lost segments.
[0137] The scheme implemented in this specification analyzes the transport layer content of data packets according to the transmission protocol to determine the port information of the data packets and uses the port information to identify data packets belonging to the same data stream; it determines the connection establishment information corresponding to the data packets based on the request information of the data packets; and it determines the connection termination information corresponding to the data packets based on the connection termination behavior in the transport layer. This achieves accurate determination of connection termination information, connection establishment information, zero-window conditions, retransmission rate, etc., of data streams on a per-stream basis, further enabling efficient and accurate determination of data stream performance indicators.
[0138] In one optional embodiment of this specification, after determining the characteristics of the data flow at each network layer, the entire process of the network analysis request from the start to the end can be segmented and quantized using quantization methods to determine the quantization result. That is, the above-mentioned generation of data flow performance indicators using the characteristics of the data flow at each network layer may include the following steps:
[0139] Obtain the lifecycle of a network analysis request;
[0140] In multiple preset segments of the lifecycle, the characteristics of the data stream corresponding to the network analysis request at each layer are quantized to obtain the quantization results corresponding to multiple preset segments.
[0141] Specifically, the lifecycle of a network analysis request refers to the entire process of a network request from its inception to its termination.
[0142] For example, by using quantitative methods, the entire process of a request from start to finish can be segmented and quantified, such as the Transmission Control Protocol (TCP) connection establishment, Secure Sockets Layer (SSL) connection establishment, first packet time, and transmission time. Combined with indicators such as retransmission rate and download speed, bottlenecks can be analyzed. For example, if the TCP connection establishment time is too long, it is usually due to network routing path issues, and the scheduling logic can be optimized to select the nearest service. If the SSL connection establishment time is long, the network routing path, the processing capacity of the server's core processor, and the characteristics of the encryption algorithm should be considered.
[0143] By applying the scheme of the embodiments in this specification, the lifecycle of a network analysis request is obtained; within multiple preset segments of the lifecycle, the characteristics of the data stream corresponding to the network analysis request at each layer are quantified to obtain quantization results corresponding to multiple preset segments. This allows for a clear and concise determination of the stage where the network bottleneck is located, further enabling rapid identification of the specific network bottleneck.
[0144] In one optional embodiment of this specification, the network analysis process may further include the following steps:
[0145] Provides a storage structure for storing preset type data of the data stream; provides a general interface, which includes at least one of a data stream name acquisition interface, a data stream hierarchical feature acquisition interface, and a data packet information acquisition interface.
[0146] In response to receiving a plugin insertion request, the first plugin corresponding to the plugin insertion request is executed. The first plugin contains calls to storage structures and / or general interfaces.
[0147] In response to receiving a plugin deletion request, delete the second plugin corresponding to the plugin deletion request.
[0148] Specifically, see Figure 4 , Figure 4A schematic diagram of the storage structure in a network analysis method provided in one embodiment of this specification is shown. See also Figure 5 , Figure 5 A schematic diagram of a general interface in a network analysis method provided in one embodiment of this specification is shown. For example... Figure 4 and Figure 5 As shown, the multiple network layers also include a base layer (Base Flow). The base layer is the foundation for implementing other network layers and defines storage structures and general interfaces. The storage structures include: a structure for storing the data flow layer type, such as FlowLayerType; a structure for storing data flow information, such as FlowInfo; a structure for storing data flow packets, such as Packets; a structure for storing the data flow start time, such as StartTime; a structure for storing the data flow end time, such as EndTime; and a structure for storing the payload length of a specific layer, such as PayloadLen. The general interfaces include: an interface for retrieving flow information functions, such as FlowName; an interface for retrieving streaming layer characteristic functions, such as FlowLayer; an interface for retrieving detailed information about each packet in the data flow, such as FlowPackets; an interface for retrieving data packets sent from a specific party in the data flow, such as FlowPacketsFromAddress; and an interface for retrieving functions to destroy the corresponding data flow, such as DestroyFlow.
[0149] It should be noted that the first plug-in in the embodiments of this specification can realize the calling of the storage structure, the calling of the general interface, and further, it can realize such as Figure 3 The network analysis method provided.
[0150] The scheme implemented in this specification provides a storage structure for storing preset type data of a data stream; it also provides a general interface, including at least one of a data stream name acquisition interface, a data stream hierarchical feature acquisition interface, and a data packet information acquisition interface; in response to receiving a plugin insertion request, it runs a first plugin corresponding to the plugin insertion request, the first plugin containing calls to the storage structure and / or the general interface; and in response to receiving a plugin deletion request, it deletes a second plugin corresponding to the plugin deletion request. By supporting a general interface and pluggable development during network analysis, users can flexibly add components, resulting in strong scalability.
[0151] The following is in conjunction with the appendix Figure 6Taking the application of the network analysis method provided in this specification in edge computing as an example, the network analysis method will be further explained. Figure 6 The present specification illustrates a flowchart of a network analysis method according to an embodiment, which includes the following steps:
[0152] Step 602: At the data link layer, using preset data packet filtering conditions, filter the data packets in the data stream passing through the data link layer to obtain the data packets to be analyzed.
[0153] Step 604: Identify the content of the data packets to be analyzed in the data stream and determine the application layer content in the data packets.
[0154] Step 606: Match the content of the application layer according to the preset matching conditions, and take the data packets that meet the preset matching conditions as the updated data packets to be analyzed.
[0155] Step 608: According to the layered network protocol, the content of the updated data packet to be analyzed is layered to obtain the content corresponding to multiple network layers of the data packet.
[0156] Step 610: Analyze the data link layer content in the data packet according to the multiple access control protocol, determine the dual-end hardware addresses of the data packet, use the dual-end hardware addresses to identify data packets belonging to the same data stream, and analyze the network card information corresponding to the data stream based on the dual-end hardware addresses of the data packet.
[0157] Step 612: Analyze the network layer content in the data packet according to the network address protocol, determine the network address of the data packet, and use the network address to identify data packets belonging to the same data stream.
[0158] Step 614: Use the Time-to-Live (TTL) value recorded in the network layer of the data packet to determine the packet capture location.
[0159] Step 616: Determine the version information of the Network Address Protocol (NAT) based on the header value of the NAT.
[0160] Step 618: Analyze the content corresponding to the transport layer in the data packet according to the transmission protocol, determine the port information of the data packet, and use the port information to identify data packets belonging to the same data stream.
[0161] Step 620: Determine the connection information corresponding to the data packet based on the request information of the data packet.
[0162] Step 622: Determine the disconnection information corresponding to the data packet based on the disconnection behavior in the transport layer.
[0163] Step 624: Obtain the lifecycle of the network analysis request.
[0164] Step 626: In multiple preset segments of the lifecycle, quantize the characteristics of the data stream corresponding to the network analysis request at each layer to obtain the quantization results corresponding to multiple preset segments.
[0165] It should be noted that the specific implementation methods of steps 602 to 626 are the same as those described above. Figure 3 The implementation methods of the provided network analysis methods are the same, so the embodiments in this specification will not be described again.
[0166] The solution provided by the embodiments in this specification offers a precise, efficient, and low-power traffic capture solution that can accurately capture target traffic passing through the host network card in high-traffic edge computing scenarios, thereby reducing the consumption of host hardware resources and minimizing the impact on other caching services on edge computing nodes.
[0167] The network analysis system provided in this specification mainly comprises two components: a traffic capture component and a performance analysis component. The traffic capture component uses a lightweight method to capture data packets passing through the network interface card (NIC), filters and analyzes these packets according to rules to obtain the target traffic. Then, a cloud storage component persistently stores the target traffic data packets. Finally, the performance analysis component analyzes the data packets to identify bottlenecks affecting network performance and uncover areas for improvement.
[0168] See Figure 7 , Figure 7 This document illustrates a flowchart of a traffic capture component in a network analysis system according to an embodiment of this specification. In kernel mode, the traffic capture component filters data packets received from the data link layer by the driver network interface card using preset packet filtering conditions to obtain the data packets to be analyzed, thereby narrowing down the scope of the target traffic. In user mode, the component captures the data packets to be analyzed through a packet capture interface, then performs traffic correlation, splitting data packets belonging to different flows for separate processing. Next, payload extraction is performed, extracting the effective payload of each data packet. Using deep packet inspection technology, regular expression matching is applied to the application layer traffic content to obtain the target traffic. Then, using preset transmission parameters and the transmission parameters of the data packets to be analyzed, slow speed judgment, retransmission rate judgment, and file size filtering are performed, and data packets that meet the preset transmission parameters are used as updated data packets to be analyzed. Finally, using a timed disk write method, the data packets to be analyzed in memory are promptly written to the hard disk for persistent storage, and then the memory is promptly released to avoid the impact of continuously increasing memory usage on other service processes. Finally, the hard disk space is released, and the data is transferred to cloud persistent storage.
[0169] The solution implemented in this specification utilizes deep packet inspection technology to flexibly filter traffic at the application layer, accurately capturing traffic based on domain names, header keywords, etc., and supports separate matching of client-side and server-side payloads. It supports calculating retransmission rate, download speed, and file size metrics, and can capture target traffic such as weak network traffic with high retransmission rates, slow streams, and large file streams. Furthermore, it provides a method for protecting the host machine by reducing memory usage through real-time disk persistence, allowing operation in safe mode without affecting other services on the host machine, and supporting uploads to cloud storage.
[0170] See Figure 8 , Figure 8 This document illustrates a processing flowchart of a performance analysis component in a network analysis system according to one embodiment of this specification. The traffic analysis component is responsible for network characteristic analysis and supports the analysis of packet capture files. These capture files can come from the traffic capture component provided in this embodiment, or from other packet capture tools, depending on the specific circumstances. This embodiment does not impose any limitations on this selection.
[0171] like Figure 8 As shown, the traffic analysis component includes a multi-layered streaming analysis model and general interfaces for each layer. The streaming analysis model is an abstraction based on a model encompassing the application layer, transport layer, network layer, data link layer, and physical layer. After reading the contents of the data packets to be analyzed from the data packet file set, the data enters the streaming model, which comprises four layers: the base layer (physical layer), data link layer, network layer, and transport layer. The base layer is the foundation for implementing the other layers of the streaming model, defining the storage structure and general interfaces. The core functions of the data link layer are: supporting multi-access control protocol data stream splitting and network interface card (NIC) traffic statistics, and supporting data link layer feature analysis. The core functions of the network layer are: identifying data packets through the network address protocol, supporting network address protocol data stream (IP data stream) splitting, network address protocol version (IP protocol version) determination, and packet capture location determination. The core functions of the transport layer are: supporting data stream splitting, Transmission Control Protocol (TCP) and User Datagram Protocol (UDP), using network address and port as unique identifiers for data streams, and taking TCP as an example, supporting TCP connection handshake analysis, TCP connection termination analysis, zero window analysis, retransmission rate analysis, and analysis of common TCP header values.
[0172] like Figure 8As shown, based on the above streaming model, application layer analysis functions can also be implemented. The server's processing capacity can be inferred through the first packet time analysis function; bottlenecks in the handshake phase can be identified through the Secure Sockets Layer (SSL) or Secure Transport Layer (TLS) handshake analysis function; appropriate encryption suites can be used in different scenarios through the cipher suite analysis function; the application protocol versions used by different customers and vendors can be understood through version analysis; and the behavior of Keep-Alive (a connection status detection mechanism) can be analyzed through its characteristics, removing the gaps between multiple HTTP / HTTPS requests (called Keep-Alive Duration), making the transmission speed indicators more accurate and precisely reflect the network status. In practical applications, the first packet time can be calculated using the following formula (6), and the TLS handshake time can be calculated using the following formula (7):
[0173] T2=t1(s_h_ack)-t2(c_h_r) (6)
[0174] T3=t1(s_nc)-t2(c_h) (7)
[0175] Where t1(s_h_ack) represents the moment when the server responds to the first packet of the client's request, t2(s_h_r) represents the moment when the client makes the HTTP request, t1(s_nc) represents the moment when the server creates a new session ticket or changes the cipher spec, and t2(c_h) represents the moment when the client sends a message to the server (client hello).
[0176] like Figure 8As shown, by determining the packet capture location, if the packet capture is on the client side, the calculated value of the above formula (6) includes the network transmission time and the server-side data preparation time. Removing the network transmission time gives the server-side data preparation time. If the packet capture is on the server side, the above formula (6) calculates the server-side data preparation time. The server-side data preparation time can reflect the server's processing capability. Since the secure transport layer protocol header value records the version of the encryption suite, a more complex encryption algorithm can be used if there are high security requirements by using a dictionary of versions and corresponding characteristics. By quantifying requests, the entire process of a request from start to finish is segmented and quantified. For example, the connection establishment time of Transmission Control Protocol (TCP) is quantified, the connection establishment time of Secure Sockets Layer (SSL) is quantified (including S1: SSL Client Hello; S2: SSL Server Hello; S3: SSL Client Key Exchange; S4: SSL Server Change Cipher), the first packet time, and the transmission time are quantified. Combined with indicators such as retransmission rate and download speed, the overall system performance can be analyzed. For example, if the Transmission Control Protocol connection establishment time is too long, it is usually due to the network routing path process. The scheduling logic can be optimized to select the nearest service. If the Secure Sockets Layer connection establishment time is long, the network routing path, the processing capacity of the server's core processor, and the characteristics of the encryption algorithm should be considered.
[0177] The traffic analysis component, using the solutions described in the embodiments of this specification, provides a multi-layered streaming model, supporting streaming at the data link layer, network layer, and transport layer, and supporting characteristic analysis at each layer. Simultaneously, it supports application layer characteristic analysis functions, ultimately forming a time quantification scheme for each stage of the request level, quickly identifying bottlenecks.
[0178] Corresponding to the above method embodiments, this specification also provides embodiments of network analysis devices. Figure 9 A schematic diagram of a network analysis device according to one embodiment of this specification is shown. Figure 9 As shown, the device includes:
[0179] Module 902 is configured to acquire data packets from the data stream;
[0180] Layering module 904 is configured to obtain the content corresponding to multiple network layers of data packets according to the layered network protocol;
[0181] Analysis module 906 is configured to analyze the characteristics of the data stream at each network layer by utilizing the content corresponding to multiple network layers of the data packet;
[0182] The generation module 908 is configured to generate performance metrics of the data stream by utilizing the characteristics of the data stream at each network layer.
[0183] Optionally, the acquisition module 902 is further configured to filter data packets in the data stream passing through the data link layer using preset data packet filtering conditions at the data link layer to obtain the data packets to be analyzed.
[0184] Optionally, the acquisition module 902 is further configured to identify the content of the data packets to be analyzed in the data stream, determine the application layer content in the data packets, match the application layer content according to preset matching conditions, and take the data packets that meet the preset matching conditions as the updated data packets to be analyzed.
[0185] Optionally, the acquisition module 902 is further configured to calculate the transmission parameters of the data packets to be analyzed in the data stream, wherein the transmission parameters include at least one of transmission speed, retransmission index and transmission size; and using preset transmission parameter conditions and the transmission parameters of the data packets to be analyzed, data packets that meet the preset transmission parameter conditions are used as updated data packets to be analyzed.
[0186] Optionally, the device further includes a storage module configured to store data packets to persistent storage and delete data packets from memory.
[0187] Optionally, the multiple network layers include the data link layer; the analysis module 906 is further configured to analyze the content corresponding to the data link layer in the data packet according to the multiple access control protocol, determine the dual-end hardware addresses of the data packet; use the dual-end hardware addresses to identify data packets belonging to the same data stream; and analyze the network interface card information corresponding to the data stream based on the dual-end hardware addresses of the data packet.
[0188] Optionally, the multiple network layers include a network layer; the analysis module 906 is further configured to perform at least one of the following: analyze the content corresponding to the network layer in the data packet according to the network address protocol, determine the network address of the data packet, and use the network address to identify data packets belonging to the same data stream; determine the packet capture location of the data packet using the time-to-live value recorded in the network layer of the data packet; and determine the version information of the network address protocol according to the header value of the network address protocol.
[0189] Optionally, the multiple network layers include a transport layer; the analysis module 906 is further configured to perform at least one of the following: analyze the content corresponding to the transport layer in the data packet according to the transport protocol, determine the port information of the data packet, and use the port information to identify data packets belonging to the same data stream; determine the connection establishment information corresponding to the data packet according to the request information of the data packet; and determine the connection termination information corresponding to the data packet according to the disconnection behavior in the transport layer.
[0190] Optionally, the generation module 908 is further configured to obtain the lifecycle of the network analysis request; and to quantize the characteristics of the data stream corresponding to the network analysis request at each layer in multiple preset segments of the lifecycle to obtain quantization results corresponding to multiple preset segments.
[0191] Optionally, the device also provides a storage structure for storing preset type data of the data stream; provides a general interface, including at least one of a data stream name acquisition interface, a data stream hierarchical feature acquisition interface, and a data packet information acquisition interface; the device further includes: a running module configured to run a first plugin corresponding to a plugin insertion request in response to receiving a plugin insertion request, the first plugin containing calls to the storage structure and / or the general interface; and a deletion module configured to delete a second plugin corresponding to a plugin deletion request in response to receiving a plugin deletion request.
[0192] The scheme described in this specification involves acquiring data packets from a data stream; obtaining the content corresponding to multiple network layers of the data packets according to a layered network protocol; analyzing the characteristics of the data stream at each network layer using the content corresponding to the multiple network layers of the data packets; and generating performance indicators for the data stream using the characteristics of the data stream at each network layer. By obtaining the content corresponding to multiple network layers of the data packets according to the layered network protocol, and further using the content corresponding to multiple network layers to determine the characteristics of the data stream at each network layer, the system achieves automatic and accurate analysis of the characteristics of the data stream in each network layer, efficiently and accurately determining the performance indicators of the data stream, thereby quickly identifying network bottlenecks.
[0193] The above is a schematic representation of a network analysis device according to this embodiment. It should be noted that the technical solution of this network analysis device and the technical solution of the network analysis method described above belong to the same concept. Details not described in detail in the technical solution of the network analysis device can be found in the description of the technical solution of the network analysis method described above.
[0194] Figure 10 This specification illustrates a structural block diagram of a computing device according to one embodiment. The components of the computing device 1000 include, but are not limited to, a memory 1010 and a processor 1020. The processor 1020 is connected to the memory 1010 via a bus 1030, and a database 1050 is used to store data.
[0195] The computing device 1000 also includes an access device 1040, which enables the computing device 1000 to communicate via one or more networks 1060. Examples of these networks include Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or combinations of communication networks such as the Internet. The access device 1040 may include one or more of any type of wired or wireless network interface (e.g., Network Interface Card (NIC)), such as an IEEE 802.11 Wireless Local Area Networks (WLAN) interface, a Wi-MAX (World Interoperability for Microwave Access) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC) interface, and so on.
[0196] In one embodiment of this specification, the above-described components of the computing device 1000 and Figure 10 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 10 The block diagram of the computing device shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed.
[0197] The computing device 1000 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or personal computers (PCs). The computing device 1000 can also be a mobile or stationary server.
[0198] The processor 1020 is used to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the above-described network analysis method.
[0199] The above is an illustrative scheme of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the network analysis method described above belong to the same concept. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the network analysis method described above.
[0200] An embodiment of this specification also provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the network analysis method described above.
[0201] The above is an illustrative scheme of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the network analysis method described above belong to the same concept. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the network analysis method described above.
[0202] An embodiment of this specification also provides a computer program, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the above-described network analysis method.
[0203] The above is an illustrative example of a computer program according to this embodiment. It should be noted that the technical solution of this computer program and the technical solution of the network analysis method described above belong to the same concept. Details not described in detail in the computer program's technical solution can be found in the description of the technical solution of the network analysis method described above.
[0204] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0205] The computer instructions include computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0206] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments in this specification are not limited to the described order of actions, because according to the embodiments in this specification, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments in this specification.
[0207] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0208] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the embodiments described herein. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the embodiments, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.
Claims
1. A network analysis system, comprising: Server and network interface card; The network interface card is configured to transmit data streams; The server is configured to obtain data packets from the data stream from the network interface card; According to the layered network protocol, obtain the content corresponding to multiple network layers of the data packet; use the content corresponding to multiple network layers of the data packet to analyze the characteristics of the data stream at each network layer; The lifecycle of a network analysis request is obtained. Taking a single network analysis request as a unit, the characteristics of the data stream corresponding to the network analysis request are quantified on each network layer to generate a performance index of the data stream. The characteristics are the performance information of the data stream on each network layer, and the performance index is used to evaluate the network performance of the data stream.
2. A network analysis method, comprising: Retrieve data packets from the data stream; According to the layered network protocol, obtain the content corresponding to multiple network layers of the data packet; By utilizing the content corresponding to multiple network layers of the data packet, the characteristics of the data stream at each network layer are analyzed, wherein the characteristics are the performance information of the data stream at each network layer; The lifecycle of a network analysis request is obtained. Taking a single network analysis request as a unit, the characteristics of the data stream corresponding to the network analysis request at each network layer are quantified to generate a performance index for the data stream. The performance index is used to evaluate the network performance of the data stream.
3. The method according to claim 2, wherein acquiring data packets in the data stream comprises: At the data link layer, preset data packet filtering conditions are used to filter data packets in the data stream passing through the data link layer to obtain the data packets to be analyzed.
4. The method according to claim 2, wherein acquiring data packets in the data stream comprises: The content of the data packets to be analyzed in the data stream is identified to determine the application layer content in the data packets; The content of the application layer is matched according to preset matching conditions, and the data packets that meet the preset matching conditions are used as updated data packets to be analyzed.
5. The method according to claim 2, wherein acquiring data packets in the data stream comprises: Calculate the transmission parameters of the data packets to be analyzed in the data stream, wherein the transmission parameters include at least one of transmission speed, retransmission index and transmission size; Using preset transmission parameter conditions and the transmission parameters of the data packet to be analyzed, data packets that meet the preset transmission parameter conditions are used as updated data packets to be analyzed.
6. The method according to any one of claims 2-5, further comprising, after acquiring the data packets in the data stream: The data packet is stored in persistent storage and then deleted from memory.
7. The method according to claim 2, wherein the plurality of network layers includes a data link layer; the step of analyzing the characteristics of the data stream at each network layer using the content corresponding to the plurality of network layers of the data packet includes: The data link layer content in the data packet is analyzed according to the multiple access control protocol to determine the dual-end hardware addresses of the data packet. The dual-end hardware address is used to identify data packets belonging to the same data stream; Based on the hardware addresses at both ends of the data packet, analyze the network interface card information corresponding to the data stream.
8. The method according to claim 2, wherein the plurality of network layers includes network layers; the step of analyzing the characteristics of the data stream at each network layer using the content corresponding to the plurality of network layers of the data packet includes at least one of the following: The network layer content in the data packet is analyzed according to the network address protocol to determine the network address of the data packet, and the network address is used to identify data packets belonging to the same data stream; The location of the captured data packet is determined by using the time-to-live value recorded at the network layer in the data packet; The version information of the network address protocol is determined based on the header value of the network address protocol.
9. The method according to claim 2, wherein the plurality of network layers includes a transport layer; the step of analyzing the characteristics of the data stream at each network layer using the content corresponding to the plurality of network layers of the data packet includes at least one of the following: The content corresponding to the transport layer in the data packet is analyzed according to the transmission protocol to determine the port information of the data packet, and the port information is used to identify data packets belonging to the same data stream; Based on the request information in the data packet, determine the connection information corresponding to the data packet; Based on the disconnection behavior in the transport layer, the disconnection information corresponding to the data packet is determined.
10. The method according to claim 2, wherein generating performance metrics of the data stream using features of the data stream at each network layer comprises: In multiple preset segments of the lifecycle, the characteristics of the data stream corresponding to the network analysis request at each layer are quantized to obtain the quantization results corresponding to the multiple preset segments.
11. The method according to claim 2, further comprising: Provide a storage structure for storing preset type data of the data stream; A general interface is provided, which includes at least one of a data stream name acquisition interface, a data stream hierarchical feature acquisition interface, and a data packet information acquisition interface; In response to receiving a plugin insertion request, the first plugin corresponding to the plugin insertion request is executed, and the first plugin contains calls to the storage structure and / or the general interface; In response to receiving a plugin deletion request, delete the second plugin corresponding to the plugin deletion request.
12. A computing device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the network analysis method according to any one of claims 2 to 11.
13. A computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the network analysis method according to any one of claims 2 to 11.
14. A computer program, wherein, When the computer program is executed in a computer, it causes the computer to perform the steps of the network analysis method according to any one of claims 2 to 11.
Citation Information
Patent Citations
Traffic detection method and device, server and storage medium
CN115023926A
Apparatus and method for collecting and analyzing communications data
US20020105911A1