Network flow data query and display method, electronic device and storage medium

By acquiring and decoding network traffic data on batches on the control device, the problem of slow data response and display speed in distributed probe environments is solved, and user experience and data processing efficiency is improved.

CN119583409BActive Publication Date: 2025-05-16SHENZHOU LINGYUN (BEIJING) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510138048.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-16
Estimated Expiration
2045-02-08

AI Technical Summary

Technical Problem

In a distributed probe environment, when the control device acquires network traffic data from each probe and displays it in a centralized manner, due to the large amount of data, the data response speed and display speed are very slow.

Method used

A network traffic data query and display method is proposed. By obtaining network traffic data from the probe in batches and on demand, and decoding and displaying the acquired data stream locally, avoiding the acquisition of all data files on all probes at once for decoding and displaying.

Benefits of technology

It significantly improves the data response speed and data display speed of users when the client requests to query network traffic data, reduces the user's waiting time and improves the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583409B_ABST
    Figure CN119583409B_ABST
Patent Text Reader

Abstract

The present invention provides a network traffic data query and display method, an electronic device and a storage medium, and relates to the field of data processing technology. The network traffic data query and display method includes: in response to receiving a network traffic data query request, obtaining a list of data packet files that meet the network traffic data query request from a number of probes respectively; obtaining data packet files from corresponding probes according to each data packet file list; writing the data streams in each data packet file into a local data packet file in sequence according to a write strategy; decoding the data streams in the local data packet file, and returning the decoded data to the front-end interface for display. Through the scheme of the present invention, network traffic data can be obtained from the probe in batches on demand, which greatly improves the data response speed and data display speed when the user requests to query network traffic data on the client, reduces the user's waiting time, and improves the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a network flow data query and display method, an electronic device and a storage medium. Background Art

[0002] In the Internet field, probes can be used to monitor network traffic, bandwidth utilization, packet loss rate and other key network performance indicators of various Internet platforms in real time. Probes can be configured through control devices, and network traffic data detected by probes can be obtained and displayed from the configured probes.

[0003] The network traffic of major Internet platforms is usually very large, and it is often necessary to deploy multiple probes and distribute the traffic to each probe for processing and analysis. In such a distributed probe environment, a control device will manage multiple probes to centrally display the data of each probe. In a distributed probe environment, the control device obtains network traffic data from each probe and centrally displays the network traffic data obtained from each probe. Due to the large amount of data that needs to be processed, the entire data response and display speed is very slow. Summary of the invention

[0004] In view of this, the present invention proposes a network traffic data query and display method, an electronic device and a storage medium, which solves the problem that in a distributed probe environment, when a control device obtains network traffic data from each probe and centrally displays the network traffic data obtained from each probe, the entire data response speed and data display speed are very slow due to the large amount of data that needs to be processed.

[0005] On the one hand, an embodiment of the present invention provides a network traffic data query and display method, the network traffic data query and display method comprising:

[0006] In response to receiving a network flow data query request sent by a client, respectively obtaining a list of data packet files that meet the network flow data query request from a plurality of probes;

[0007] According to each data packet file list, obtain the data packet files from the corresponding probes respectively;

[0008] Write the data streams in each data packet file into the local data packet file in sequence according to the writing strategy;

[0009] Decode the data stream in the local data packet file and return the decoded data to the front-end interface for display.

[0010] In some implementations, after obtaining data packet files from corresponding probes according to each data packet file list, the network traffic data query and display method further includes:

[0011] Configure the index information of the obtained data packet file;

[0012] Write the data streams in each data packet file into the local data packet file in sequence according to the writing strategy, including:

[0013] According to the index information, read the data stream from the corresponding data packet file respectively;

[0014] Comparing the time information of each of the read data streams to select a data stream that meets a second preset condition from each of the data streams;

[0015] Write the selected data stream into a local data packet file;

[0016] Update the index information of the data packet file where the data stream that meets the second preset condition is located, and read the corresponding data stream from the data packet file where the data stream that meets the second preset condition is located according to the updated index information for decoding and display, and return to the step of comparing the time information of each data stream read.

[0017] In some implementations, after writing the selected data stream into the local data packet file, the network traffic data query and display method further includes:

[0018] Determine whether the index information of the data packet file where the data stream meeting the second preset condition is located triggers a third preset condition;

[0019] In response to the index information of the data packet file where the data stream meeting the second preset condition is located triggering the third preset condition, the next data packet file is obtained from the corresponding probe according to the corresponding data packet file list, and the index information of the next data packet file obtained is configured;

[0020] Return to the steps of reading data streams from corresponding data packet files according to index information.

[0021] In some implementations, configuring the index information of the acquired data packet file includes:

[0022] The index position of the obtained data packet file points to the starting position of the file.

[0023] In some implementations, comparing the time information of each of the read data streams to select a data stream that meets the second preset condition from each of the data streams includes:

[0024] The time information of each data stream read is compared to select the earliest data stream from each data stream.

[0025] In some implementations, decoding a data stream in a local data packet file includes:

[0026] In response to the data stream information in the local data packet file meeting the first preset condition, all data streams in the local data packet file are decoded, and the decoded data are returned to the front-end interface for display.

[0027] In some implementations, in response to data stream information in the local data packet file meeting a first preset condition, decoding all data streams in the local data packet file includes:

[0028] In response to the number of data streams in the local data packet file matching the number of decoded data that can be displayed on one page of the client display interface, all data streams in the local data packet file are decoded.

[0029] In some implementations, after returning the decoded data to the front-end interface for display, the network traffic data query and display method further includes:

[0030] In response to receiving a request to display the next page from the client, the method returns to the step of reading data streams from corresponding data packet files according to the index information.

[0031] On the other hand, an embodiment of the present invention further provides an electronic device, comprising: at least one processor; and a memory, the memory storing a computer program that can be run on the processor, characterized in that when the processor executes the program, the steps of the method of any of the above embodiments are performed.

[0032] On the other hand, an embodiment of the present invention further provides a computer storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method of any of the above embodiments are executed.

[0033] The present invention has at least the following beneficial effects:

[0034] The present invention provides a network traffic data query and display method, an electronic device and a storage medium. The network traffic data query and display method, the electronic device and the storage medium provided by the present invention can obtain network traffic data from probes in batches as needed after receiving a query request from a client, and decode and display the obtained network traffic data, without having to obtain all pcap files on all probes at one time for decoding and displaying, which greatly improves the data response speed and data display speed when a user requests to query network traffic data on the client, reduces the user's waiting time, and improves the user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other embodiments can be obtained based on these drawings without paying creative work.

[0036] Figure 1 A flowchart of a network traffic data query and display method provided by an embodiment of the present invention;

[0037] Figure 2 A flowchart of a network traffic data query and display method provided by an embodiment of the present invention;

[0038] Figure 3 A schematic diagram of the process of obtaining a pcap file from a probe in a network traffic data query and display method provided in an embodiment of the present invention;

[0039] Figure 4 A schematic diagram of a process of reading data from a pcap file obtained by a probe and writing it into a local pcap file in a network traffic data query and display method provided in an embodiment of the present invention;

[0040] Figure 5 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention;

[0041] Figure 6 A schematic diagram of the structure of a computer storage medium provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0042] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the embodiments of the present invention are further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.

[0043] It should be noted that all expressions using "first" and "second" in the embodiments of the present invention are for distinguishing two non-identical entities with the same name or non-identical parameters. It can be seen that "first" and "second" are only for the convenience of expression and should not be understood as limitations on the embodiments of the present invention. The subsequent embodiments will not explain this one by one.

[0044] Probe: An electronic device that runs a program that can capture, analyze, and save network data streams from a network card. These network data streams are stored in data packet files, and are usually stored in pieces. Each data packet file is named with the start and end timestamps of the data stream stored in it.

[0045] Control device: An electronic device that runs a program that can configure each probe and display the analysis results of the network data on each probe.

[0046] In the Internet field, probes can be used to monitor network traffic, bandwidth utilization, packet loss rate and other key network performance indicators of various Internet platforms in real time. Probes can be configured through control devices, and network traffic data detected by probes can be obtained and displayed from the configured probes.

[0047] The network traffic of major Internet platforms is usually very large, and it is often necessary to deploy multiple probes and distribute the traffic to each probe for processing and analysis. In such a distributed probe environment, a control device will manage multiple probes to centrally display the data of each probe. In a distributed probe environment, the control device obtains network traffic data from each probe and centrally displays the network traffic data obtained from each probe. Due to the large amount of data that needs to be processed, the entire data response and display speed are very slow. The inventor found that the reasons for the slow response speed and display speed of obtaining network traffic data from each probe on the control device are as follows:

[0048] The pcap (Packet Capture, which can be understood as a packet capture technology) data stream captured by each probe is usually stored in a packet file (hereinafter referred to as pcap file) on the disk of each probe. On a single probe, the pcap data streams in the pcap file are ordered. However, since the network traffic data in the same time period will be assigned to different probes for simultaneous processing, the pcap data streams between different probes are out of order.

[0049] If the central control needs to obtain network traffic data from each probe in the same time period for display, it can only download all the required pcap files to the control device at one time, decode all pcap data streams in all pcap files on the control device, and display the decoded data. Since a large number of pcap files need to be transmitted over the network, the response speed will be very slow.

[0050] For example, to query the decoding data for the hour from 10 to 11 o'clock, the usual practice is that the control device downloads all the pcap files on each probe between 10 and 11 o'clock to the control device, then merges them into a large pcap file and sorts the pcap data streams in it, and then performs decoding analysis. After decoding all the pcap data streams, the data required for the first page of the client interface is obtained and sent to the client interface for presentation. During the entire process, the control device needs to download a large number of pcap files from each probe and needs to parse a large number of pcap data streams at the same time, so the data response speed and interface display speed are very slow.

[0051] In addition, if the user only views the decoded data of the first few pages when viewing the displayed decoded data on the front-end interface, and then closes the page, and no longer views the subsequent decoded data, the subsequent decoded data is wasted.

[0052] In view of this, in order to solve at least one of the above technical problems, an embodiment of the present invention proposes a network traffic data query and display method, which can reduce the amount of data to be processed by pulling it in batches on demand, so as to quickly respond to data to the front end and reduce customer waiting time.

[0053] The present invention is described in detail below in conjunction with embodiments and drawings.

[0054] A first aspect of an embodiment of the present invention provides a network traffic data query and display method, which can be applied to a control device, such as a computer with a display function, a processor, or other electronic device.

[0055] like Figure 1 As shown, the network traffic data query and display method provided by the embodiment of the present invention may include steps S10 to S13.

[0056] S10 . In response to receiving a network traffic data query request sent by a client, obtaining a list of data packet files that meet the network traffic data query request from a plurality of probes respectively.

[0057] The network traffic data query request may be a network traffic data query request within a certain time period.

[0058] On a single probe, the pcap file is named according to the start and end time of the pcap data stream contained therein. Therefore, the pcap files listed in the pcap file list can be sorted according to the time size in the name.

[0059] When the control device receives a network traffic data query request within a certain time period from the client, it can send a corresponding query request to several probes connected to it, for example, a query request in HTTP format, to obtain a pcap file list containing all pcap file names within the specified query time period on each probe.

[0060] After each probe receives the network traffic data query request for the specified time period from the control device, it searches for all pcap files in the directory, finds the pcap files within the specified query time period based on the pcap file name, forms a pcap file list based on the file names of all the found pcap files, and sends it to the control device.

[0061] S11. Obtain data packet files from corresponding probes according to each data packet file list.

[0062] The corresponding data packet files can be obtained from the corresponding probes according to the time when the network traffic data corresponding to each data packet file in each data packet file list occurs or the time when each data packet is captured by the corresponding probe.

[0063] Since the pcap files listed in the pcap file list are sorted according to the time size in the naming, the specified data packet file can be obtained from the probe corresponding to the list according to the time size corresponding to each file name in the pcap file list. For example, the pcap file corresponding to the earliest pcap file name in the pcap file list can be obtained from the corresponding probe according to the pcap file list.

[0064] S12. Write the data streams in each data packet file into the local data packet file in sequence according to the writing strategy.

[0065] The writing strategy may be a writing strategy based on the time sequence of network traffic occurrence. For example, the writing strategy may be that the data streams in each pcap file may be sequentially written into a pre-created pcap file (i.e., a local data packet file) according to the time sequence of network traffic occurrence.

[0066] S13. Decode the data stream in the local data packet file, and return the decoded data to the front-end interface for display.

[0067] You can call a network packet capture tool, such as tshark, tcpdump, or Wireshark, to decode all data streams in the pre-created pcap file and return the decoded data to the front-end interface for display.

[0068] The timing of decoding can be set based on the actual usage scenario.

[0069] For example, you can read a data stream from a pcap file that complies with the write strategy, write a data stream whose comparison result meets the second preset condition into a pre-created pcap file, and decode the written data stream in the pre-created pcap file to obtain decoded data, and send the obtained decoded data to the client for display until all data streams required in the network data query request are parsed and decoded.

[0070] For example, you can also first read the data stream from the pcap file that complies with the writing strategy, and write the data stream whose comparison result meets the second preset condition into a pre-created pcap file, until the number of data streams in the pre-created pcap file matches the number of decoded data that can be displayed on one page of the client display interface, decode all the data streams in the pre-created pcap file, and send the decoded data to the client for display.

[0071] In the embodiment of the present invention, the pcap files stored on the probes are named according to the start and end time of the pcap data streams contained therein, thereby forming a pcap file list in which the file names are sorted by time for use by the control device. The control device can obtain the pcap files stored on each probe in the order of time from small to large according to the pcap file list, and write the pcap data streams in each obtained pcap file into a pre-created pcap file in the order of time from small to large, and decode and display the data streams in the pre-created pcap file.

[0072] Through the scheme of the embodiment of the present invention, after receiving the query request sent by the client, the control device can obtain network traffic data from the probe in batches on demand, and decode and display the obtained network traffic data. There is no need to obtain all pcap files on all probes at one time for decoding and display, which greatly improves the data response speed and data display speed when the user requests to query the network traffic data on the client, reduces the user's waiting time, and improves the user experience.

[0073] In some embodiments of the present invention, after obtaining data packet files from corresponding probes according to each data packet file list, the network traffic data query and display method of the embodiment of the present invention may further include: configuring index information of the obtained data packet files.

[0074] Specifically, the index information may include a pointer to an index position. The pointer to the index position is related to the arrangement order of the pcap data streams contained in the pcap file. When the pcap data streams contained in the pcap file are arranged in ascending order according to time, the index position can be configured to point to the starting position of the pcap file, thereby obtaining the pcap file corresponding to the earliest pcap file name in each pcap file list, and further obtaining the earliest pcap data stream in each obtained pcap file.

[0075] In a specific implementation, Figure 1 Step S12 shown in the figure, writes the data streams in each pcap file into the pre-created pcap file in sequence according to the write strategy, which may include the following: Figure 2Steps S20~S23 shown.

[0076] S20. Read data streams from corresponding pcap files according to the index information.

[0077] S21 . Compare the time information of each read data stream to select a data stream that meets a second preset condition from each data stream.

[0078] The second preset condition may be that the time of each data stream to be compared is the earliest.

[0079] S22. Write the selected data stream into a pre-created pcap file.

[0080] S23, update the index information of the pcap file where the data stream that meets the second preset condition is located, and read the corresponding data stream from the pcap file where the data stream that meets the second preset condition is located according to the updated index information, and return to step S21.

[0081] Specifically, the earliest pcap data stream can be obtained from each pcap file according to the index information of each pcap file. By comparing the time information of each read data stream, the earliest data stream can be filtered out from each data stream according to the time information (for example, timestamp) of each read data stream, and the filtered earliest data stream is written into the pre-created pcap file.

[0082] After writing the earliest filtered data stream into the pre-created pcap file, the index information of the pcap file where the earliest filtered pcap data stream is located is updated, that is, the index position in the file is pointed to the next position of the position where the above-mentioned earliest pcap data stream is located. Therefore, the next pcap data stream adjacent to the earliest filtered pcap data stream can be read from the pcap file based on the new index position, and return to step S21, so that the data streams that need to be compared in the comparison process can be updated based on the updated index information, so that the data streams in each pcap file are written into the pre-created pcap file in order from small to large in time.

[0083] In some embodiments of the present invention, Figure 2 As shown, after step S22, the network traffic data query and display method may further include steps S221~S222.

[0084] S221. Determine whether the index information of the pcap file containing the data stream meeting the second preset condition triggers a third preset condition.

[0085] The third preset condition is used to determine whether the index position points to the last data stream in the pcap file.

[0086] Determine whether the index information of the pcap file where the data stream that meets the second preset condition is located triggers the third preset condition. If the third preset condition is triggered, execute step S222; if the third preset condition is not triggered, execute step S23.

[0087] S222. According to the corresponding pcap file list, obtain the next pcap file from the corresponding probe, configure the index information of the next pcap file obtained, and return to step S20.

[0088] In some embodiments of the present invention, Figure 2 The step S21 shown, comparing the time information of each read data stream to select a data stream that meets the second preset condition from each data stream, may include: comparing the time information of each read data stream to select the earliest data stream from each data stream.

[0089] In some embodiments of the present invention, Figure 1 The S13 shown, decoding the data stream in the local data packet file, may include: in response to the data stream information in the local data packet file meeting the first preset condition, decoding all data streams in the local data packet file, and returning the decoded data to the front-end interface for display.

[0090] In some embodiments of the present invention, in response to data stream information in a local data packet file meeting a first preset condition, decoding all data streams in the local data packet file may include: in response to the number of data streams in the local data packet file meeting the number of decoded data that can be displayed on one page of a client display interface, decoding all data streams in the local data packet file.

[0091] In some embodiments of the present invention, after the decoded data is returned to the front-end interface for display, the network traffic data query and display method may also include: in response to receiving a request to display the next page from the client, returning the step of reading the data stream from the corresponding pcap file according to the index information.

[0092] Specifically, in the process of decoding the data stream, the data stream written in the pre-created pcap file can be decoded based on the amount of decoded data that can be displayed on one page of the client display interface. When receiving the display next page request sent by the client, repeat the following steps: Figure 1 The steps S11 to S13 shown are used to decode the data stream corresponding to the next interface display page to be displayed, thereby avoiding the waste of decoded data.

[0093] In some embodiments of the present invention, in order to improve the user experience and avoid the waste of decoded data, after decoding the data stream written in the pre-created pcap file based on the amount of decoded data that can be displayed on one page of the client display interface, the following steps are repeated: Figure 1 Steps S11 to S13 are shown to decode the subsequent one or several pages of data in advance, thereby allowing the user to avoid waiting when he wants to continue viewing the next page of data after viewing the decoded data displayed on the current interface.

[0094] The specific implementation of the embodiment of the present invention is described below through specific examples.

[0095] In this example, the control device communicates with two probes (probe 1 and probe 2), and the pcap file of each probe contains multiple data stream files, such as stream_time_001, stream_time_002, etc. For the convenience of description, the numbers 001, 002, etc. in the data stream file names are used to indicate the order of the time when the data stream occurs, rather than the specific time information.

[0096] S31. In response to receiving the query request sent by the client, the control device initiates a query request in HTTP format to each probe, thereby obtaining a list of all pcap file names within a specified query time period on each probe.

[0097] S32. In response to receiving the query request from the control device, the probe searches for file names whose pcap file names intersect with the query time in the query request based on the pcap file names stored on its disk, generates a pcap file list, and sends the generated pcap file list to the control device.

[0098] The file names of the pcap files on the probe are sorted according to the start and end time of the data stream stored therein, and all pcap files in the probe disk directory are searched. Therefore, according to the file name, the file name with the intersection of the data stream time and the query time is found, and a pcap file list is generated, and the generated pcap file list is sent to the control device.

[0099] S33. Reference Figure 3 After the control device receives the pcap file list sent by each probe in order of file name by time, it downloads the first pcap file on each probe to the central control and points the index to the starting position of the file.

[0100] S34, the control device internally polls the pcap files obtained from each probe, and extracts the data stream at the current index position of each pcap file.

[0101] S35, reference Figure 4 The control device compares the timestamps of the data streams taken out from the pcap files corresponding to each probe, writes the stream with the smallest timestamp into the new pcap, and increases the index on the corresponding probe pcap by 1.

[0102] S36, when the index position reaches the end of the current pcap file (i.e., no more data records can be read in the current pcap file), check whether there are other unobtained pcap files in the pcap list corresponding to the probe where the current pcap file is located. If there are still unobtained files, the control device downloads the next pcap file from this probe, and points the index to the starting position of the next Pcap, and repeats the above process.

[0103] S37. When the number of streams in the new pcap file reaches the size of a page, tshark is called to decode it and the decoded data is returned to the front end for display.

[0104] S38. When the client requests the next page, the above process is repeated to generate the Pcap corresponding to the next page for decoding and display.

[0105] In the embodiment of the present invention, the pcap files stored on the probes are named according to the start and end time of the pcap data streams contained therein, thereby forming a pcap file list in which the file names are sorted by time for use by the control device. The control device can obtain the pcap files stored on each probe in the order of time from small to large according to the pcap file list, and write the pcap data streams in each obtained pcap file into a pre-created pcap file in the order of time from small to large, and when the data stream information in the pre-created pcap file reaches a specified size, the data stream in the pre-created pcap file is decoded and displayed.

[0106] In an embodiment of the present invention, after receiving a query request from a client, the control device can obtain network traffic data from the probe in batches as needed, and decode and display the obtained network traffic data. There is no need to obtain all pcap files on all probes at one time for decoding and display, which greatly improves the data response speed and data display speed when the user requests to query network traffic data on the client, reduces the user's waiting time, and improves the user experience.

[0107] Based on the same inventive concept, according to another aspect of the present invention, Figure 5 As shown, an embodiment of the present invention further provides an electronic device 500, which includes a processor 510 and a memory 520. The memory 520 stores a computer program 521 that can be run on the processor. When the processor 510 executes the program, the steps of the above method are performed.

[0108] Among them, the memory, as a non-volatile storage medium, can be used to store non-volatile software programs, non-volatile computer executable programs and modules, such as the program instructions / modules corresponding to the compression method in the embodiment of the present application. The processor executes various functional applications and data processing of the device by running the non-volatile software programs, instructions and modules stored in the memory, that is, realizing the compression method of the above method embodiment.

[0109] The memory may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the device, etc. In addition, the memory may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the local module via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0110] Based on the same inventive concept, according to another aspect of the present invention, Figure 6 As shown, an embodiment of the present invention further provides a computer storage medium 600, which stores a computer program 610 for executing the above method when executed by a processor.

[0111] Finally, it should be noted that a person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, the storage medium of the program can be a disk, an optical disk, a read-only storage memory (ROM) or a random access memory (RAM), etc. The above-mentioned computer program embodiments can achieve the same or similar effects as the corresponding above-mentioned any method embodiments.

[0112] It will also be appreciated by those skilled in the art that various exemplary logic blocks, modules, circuits and algorithm steps described in conjunction with the disclosure herein can be implemented as electronic hardware, computer software or a combination of the two. In order to clearly illustrate this interchangeability of hardware and software, a general description has been given to the functions of various schematic components, blocks, modules, circuits and steps. Whether this function is implemented as software or hardware depends on specific applications and the design constraints imposed on the entire system. Those skilled in the art can implement the function in various ways for each specific application, but this implementation decision should not be interpreted as causing a departure from the disclosed scope of the embodiments of the present invention.

[0113] The above are exemplary embodiments disclosed in the present invention, but it should be noted that various changes and modifications may be made without departing from the scope of the embodiments disclosed in the present invention as defined in the claims. The functions, steps and / or actions of the method claims according to the disclosed embodiments described herein do not need to be performed in any particular order. The serial numbers of the embodiments disclosed in the above embodiments of the present invention are for description only and do not represent the advantages and disadvantages of the embodiments. In addition, although the elements disclosed in the embodiments of the present invention may be described or required in individual form, they may also be understood as multiple unless explicitly limited to the singular.

[0114] It should be understood that, as used herein, the singular forms "a", "an" are intended to include the plural forms as well, unless the context clearly supports an exception. It should also be understood that, as used herein, "and / or" refers to any and all possible combinations including one or more of the associated listed items.

[0115] A person skilled in the art should understand that the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the disclosure of the embodiments of the present invention (including the claims) is limited to these examples; under the concept of the embodiments of the present invention, the technical features in the above embodiments or different embodiments can also be combined, and there are many other changes in different aspects of the above embodiments of the present invention, which are not provided in detail for the sake of simplicity. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present invention should be included in the protection scope of the embodiments of the present invention.

Claims

1. A network traffic data query and display method, characterized in that: The method comprises: In response to receiving a network traffic data query request sent by a client, a list of data packet files that meet the network traffic data query request is obtained from a plurality of probes respectively; wherein the list of data packet files is dynamically generated based on the network traffic data query request sent by the client, and the list of data packet files includes name information of a plurality of pcap files sorted in chronological order; According to each data packet file list, obtain the earliest data packet file from the corresponding probe; Configure the index information of the obtained data packet file; According to the index information, read the data streams from the corresponding data packet files respectively; Compare the time information of each data stream read to select a data stream that meets a second preset condition from each data stream; wherein the second preset condition is the earliest occurrence time; Write the selected data stream into a local data packet file; Determine whether the index information of the data packet file where the data stream meeting the second preset condition is located triggers a third preset condition; In response to the index information of the data packet file where the data stream meeting the second preset condition is located triggering the third preset condition, according to the corresponding data packet file list, the next data packet file is obtained from the corresponding probe, and the index information of the next data packet file obtained is configured; returning to the step of reading the data streams from the corresponding data packet files respectively according to the index information; In response to the third preset condition not being triggered, the index information of the data packet file where the data stream that meets the second preset condition is located is updated, and the corresponding data stream is read from the data packet file where the data stream that meets the second preset condition is located according to the updated index information, and the step of returning to compare the time information of each read data stream is performed; wherein the third preset condition is used to determine whether the index information points to the last data stream in the data packet file; In response to the number of data streams in the local data packet file meeting the number of decoded data that can be displayed on one page of the client display interface, all data streams in the local data packet file are decoded, and the decoded data is returned to the front-end interface for display.

2. The method according to claim 1, characterized in that Configure the index information of the obtained data packet file, including: The index position of the acquired data packet file is pointed to the starting position of the file.

3. The method according to claim 1, characterized in that After returning the decoded data to the front-end interface for display, the method further includes: In response to receiving a request to display the next page sent by the client, returning to the step of reading data streams from corresponding data packet files according to the index information.

4. An electronic device, comprising: at least one processor; as well as A memory storing a computer program executable on the processor, wherein the processor executes the steps of the method according to any one of claims 1 to 3 when executing the program.

5. A computer storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 3 are performed.

Citation Information

Patent Citations

  • Method for browsing decoded ticket file

    CN103699699A

  • Data packet storage and query method, device and system and storage medium

    CN113220684A