Monitoring method, system and equipment based on socket in gateway equipment and medium

By adding tracking points of socket functions to the tracking framework of home gateway devices, the problem of detecting and locating abnormal behavior of gateway devices is solved, real-time monitoring and exception handling of data interaction is realized, and the visibility and security of the device are enhanced.

CN120034455APending Publication Date: 2025-05-23FIBERHOME TELECOMMUNICATION TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510138676.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In home gateway devices, it is difficult to detect and locate abnormal behaviors of specific programs frequently sending and receiving packages for a long time. Existing tools are not suitable for use on embedded devices with resource-constrained resources.

Method used

In the tracking framework of gateway devices, a tracking point function is added for the socket function of data interaction, and the socket messages flowing through the socket function are tracked and counted through the tracking point function, the data is summarized and the preconfigured conditions are compared, and exceptions are handled according to the preset scheme.

Benefits of technology

Real-time monitoring and tracking of the data interaction process of gateway equipment is realized, visibility and monitoring capabilities are enhanced, abnormal situations are discovered in a timely manner, and problems are quickly responded and solved, avoiding potential risks and losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034455A_ABST
    Figure CN120034455A_ABST
Patent Text Reader

Abstract

The invention relates to a monitoring method and system based on sockets in gateway equipment, equipment and a medium. The monitoring method comprises the following steps: starting a tracking framework in gateway equipment, and adding a tracking point function to a socket function for data interaction through the tracking framework; the socket messages flowing through the socket function are tracked through the tracking point function, and summarized data of the socket messages are obtained through statistics; and comparing the summarized data with a pre-configured condition, and processing according to a preset scheme when the summarized data does not meet the pre-configured condition. According to the scheme, the visibility and monitoring capability of the gateway equipment to the data interaction process are greatly enhanced, abnormal conditions in data interaction are found in time, when the summarized data do not meet the preset conditions, processing is carried out according to the preset scheme, rapid response and problem solving are facilitated, and potential risks and losses are avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure belongs to the technical field of data monitoring, and in particular, relates to a monitoring method, system, electronic device and storage medium based on a socket in a gateway device. Background Art

[0002] In the testing or engineering application of home gateway equipment, it is often difficult to detect and locate abnormal behaviors such as long-term frequent sending and receiving of packets by specific programs.

[0003] Home gateway devices are usually Linux systems. To address the above issues, in the field of network monitoring of Linux systems, there are currently tools based on traditional fixed counters and related tools. Although they can monitor socket I / O, they cannot perform statistics by process. Some third-party tools that have the function of distinguishing process information are not suitable for implementation in resource-constrained embedded devices such as home gateways because of the dependence and high overhead of the technology they use. Summary of the invention

[0004] To solve the above problems, the present disclosure provides a monitoring method, system, electronic device and storage medium based on sockets in a gateway device. The solution can timely detect abnormal situations in data interaction, help to quickly respond and solve problems, and avoid potential risks and losses.

[0005] In order to solve the above technical problems, the first aspect of the present invention proposes a monitoring method based on a socket in a gateway device, the method comprising:

[0006] Opening a tracing framework in the gateway device, and adding a tracing point function to a socket function for data interaction through the tracing framework;

[0007] Tracking the socket message flowing through the socket function through the tracking point function, and obtaining summary data of the socket message by statistics;

[0008] The summary data is compared with a pre-configured condition, and when the summary data does not meet the pre-configured condition, it is processed according to a pre-set solution.

[0009] According to a preferred embodiment of the present invention, adding a tracking point function to a socket function for data interaction through the tracking framework includes:

[0010] A tracking point function is added to a socket message sending function and a socket message receiving function through the tracking framework; the tracking point function includes: a function for obtaining the number of socket messages and the amount of data.

[0011] According to a preferred implementation manner of the present invention, the tracking of the socket message flowing through the socket function by the tracking point function and obtaining statistical summary data of the socket message include:

[0012] Enabling the tracking point function based on a preset period or when a tracking demand is received, and tracking the socket message flowing through the socket message sending function and the socket message receiving function;

[0013] The tracked socket messages are analyzed, and the number of received data, the number of sent data, the amount of received data, and the amount of sent data in the socket messages of each process within a preset time period are statistically obtained as the summary data.

[0014] According to a preferred embodiment of the present invention, comparing the summary data with a pre-configured condition and processing the summary data according to a pre-set solution when the summary data does not meet the pre-configured condition includes:

[0015] Compare the number of received data and the number of sent data of each process within a preset time period with the preset number of data processed;

[0016] When the number of received data and / or the number of sent data exceeds the preset number of data to be processed, a warning is issued, and / or the process that exceeds the preset number of data to be processed is restarted.

[0017] According to a preferred implementation manner of the present invention, the monitoring method further comprises: configuring different preset data processing numbers for different processes.

[0018] According to a preferred embodiment of the present invention, comparing the summary data with a pre-configured condition and processing the summary data according to a pre-set solution when the summary data does not meet the pre-configured condition includes:

[0019] Compare the amount of data received and sent by each process within a preset time period with the preset data processing amount;

[0020] When the amount of received data and / or the amount of sent data exceeds the preset data processing amount, a warning is issued, and / or the process that exceeds the preset data processing amount is restarted.

[0021] According to a preferred implementation manner of the present invention, the monitoring method further comprises: configuring different preset data processing volumes for different processes.

[0022] In order to solve the above technical problem, the second aspect of the present invention proposes a monitoring system based on a socket in a gateway device, the monitoring system comprising:

[0023] A tracking point module, used to enable a tracking framework in the gateway device, and to add a tracking point function to a socket function for data interaction through the tracking framework;

[0024] A tracker module, used for tracking the socket message flowing through the socket function through the tracking point function;

[0025] A statistical summary module, used for obtaining summary data of the socket message by statistics;

[0026] The monitoring module is used to compare the summary data with pre-configured conditions and to process the summary data according to a pre-set solution when the summary data does not meet the pre-configured conditions.

[0027] In order to solve the above technical problem, the third aspect of the present invention provides an electronic device, comprising:

[0028] Processor; and

[0029] A memory storing computer executable instructions, wherein when the computer executable instructions are executed, the processor executes the method described in any one of the above embodiments.

[0030] In order to solve the above technical problems, the fourth aspect of the present invention proposes a computer storage medium, wherein the computer storage medium stores one or more programs, and when the one or more programs are executed by a processor, the method described in any one of the above embodiments is implemented.

[0031] Compared with the prior art, the present disclosure has the following advantages: by adding tracking point functions to the socket functions of data interaction in the tracking framework of the gateway device, the present disclosure can monitor and track the socket messages flowing through these functions in real time, which greatly enhances the visibility and monitoring ability of the gateway device to the data interaction process. By summarizing and counting the socket messages and comparing them with pre-configured conditions, anomalies in data interaction can be discovered in time. When the summarized data does not meet the preset conditions, it is processed according to the pre-set plan, which helps to quickly respond to and solve problems and avoid potential risks and losses.

[0032] Other features and advantages of the present disclosure will be described in the following description, and partly become apparent from the description, or be understood by implementing the present disclosure. The purpose and other advantages of the present disclosure can be realized and obtained by the structures pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0034] Figure 1 A first flow chart of a monitoring method based on a socket in a gateway device according to an embodiment of the present disclosure is shown;

[0035] Figure 2 A schematic diagram of data flow through a kernel function according to an embodiment of the present disclosure is shown;

[0036] Figure 3 A second flow chart of a monitoring method based on a socket in a gateway device according to an embodiment of the present disclosure is shown;

[0037] Figure 4 A first flow chart of a method for determining whether a gateway device is abnormal based on summary data according to an embodiment of the present disclosure is shown;

[0038] Figure 5 A second flow chart of a method for determining whether a gateway device is abnormal based on summary data according to an embodiment of the present disclosure is shown;

[0039] Figure 6 A third flow chart of a monitoring method based on a socket in a gateway device according to an embodiment of the present disclosure is shown;

[0040] Figure 7 A schematic diagram of the structure of a monitoring system based on a socket in a gateway device according to an embodiment of the present disclosure is shown;

[0041] Figure 8 A schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0042] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.

[0043] The same reference numerals in the drawings represent the same or similar elements, components or parts, and thus the repeated description of the same or similar elements, components or parts may be omitted below. It should also be understood that although the first, second, third and other attributives representing the numbers may be used herein to describe various devices, elements, components or parts, these devices, elements, components or parts should not be limited by these attributives. In other words, these attributives are only used to distinguish one from another. For example, the first device may also be called the second device, but it does not deviate from the essential technical solution of the present invention. In addition, the terms "and / or" and "and / or" refer to all combinations including any one or more of the listed items.

[0044] See also Figure 1 , Figure 1 This is a flow chart of a monitoring method based on a socket in a gateway device provided by the present invention, as shown in FIG. Figure 1 As shown, the monitoring method includes:

[0045] S11. Start the tracking framework in the gateway device, and add a tracking point function to the socket function for data interaction through the tracking framework.

[0046] In this embodiment, a gateway device, also known as an internetwork connector or a protocol converter, is a computer system or device that provides data conversion services between multiple networks.

[0047] In this embodiment, the so-called socket is an abstraction of the endpoint for bidirectional communication between application processes on different hosts in the network. A socket is one end of process communication on the network, providing a mechanism for application layer processes to exchange data using network protocols. In terms of its position, the socket is connected to the application process at the top and the network protocol stack at the bottom. It is the interface for the application to communicate through the network protocol and the interface for the application to interact with the network protocol stack.

[0048] In this embodiment, the socket function is a series of key functions used for creation, management and communication when performing network programming. These functions are usually encapsulated in a specific dynamic link library and need to be referenced through a corresponding header file.

[0049] In this embodiment, a tracking point is added to the socket function for data interaction through the tracking framework in the gateway device. Specifically, the kernel option of the ftrace tracking framework is enabled in the Linux kernel of the gateway device, and a tracking point is added / enabled in the kernel functions sock_sendmsg() and sock_recvmsg() of the Linux kernel. The tracking point contains information such as the number of packets, the amount of bytes in the packet, and the protocol of the socket. ftrace is a powerful tracking tool in the Linux kernel, and its full name is Function Tracer. sock_sendmsg() is a function in the Linux kernel for sending messages through a socket. sock_recvmsg() is a function in the Linux kernel for processing received network data.

[0050] Specifically, a tracking point function is added to the socket message sending function and the socket message receiving function through the tracking framework; the tracking point function includes: a function for obtaining the number of socket messages and the amount of data.

[0051] S12. Track the socket message flowing through the socket function through the tracking point function, and obtain summary data of the socket message by statistics.

[0052] In this embodiment, the embodiment of the present invention relies on the kernel functions sock_sendmsg() and sock_recvmsg(), that is, the socket messages flowing through the kernel functions sock_sendmsg() and sock_recvmsg() are tracked and sampled. Therefore, the target process needs to satisfy the system calls such as send() / sendto(), recv() / recvfrom(), write() / read() used by the socket sending and receiving functions, otherwise it is not within the statistical range.

[0053] Specifically, Figure 2 As shown, in a specific embodiment, a schematic diagram of the data flow through the kernel function is shown. Taking App as an example, data is written in App through the SSL_write function, and messages are sent through the send() / sendto() / sendmsg() / write() functions via sock_sendmsg(); messages are received via sock_recvmsg() and passed to the recv() / recvfrom() / recvmsg() / read() functions, and data is read through the SSL_read function and passed to App; the SSL_write function is a function in the OpenSSL library, which is used to write data to the SSL connection; the SSL_read function is a function in the OpenSSL library used to read data from the SSL / TLS connection.

[0054] ftrace mainly consists of two parts: framework core and tracers. Framework core: manages various tracers, uses the tracefs file system to provide configuration options to user space and output trace information. Tracer: implements different tracing functions, such as function call tracing, function call graph tracing, etc., and saves trace information to the Ring Buffer.

[0055] The tracepoint module is used to read the functions for setting tracepoints in the kernel functions sock_sendmsg() and sock_recvmsg() and obtaining the socket message data at the tracepoints. The tracepoint function is enabled through the tracer module to track the socket messages passing through the socket message sending function and the socket message receiving function, and send them to the Ring Buffer. The tracefs file is used for statistics to generate summary data. The statistical summary module reads the data in the tracefs file. Finally, the monitoring module extracts the summary data from the statistical summary module.

[0056] In this embodiment, the tracking point event in the ftrace tracking framework is enabled to track the socket messages flowing through sock_sendmsg() and sock_recvmsg(); in order to detect whether the data interaction in the system is abnormal, the tracking can be stopped after a period of time, and the interaction data received during this period can be used to determine whether the interaction is abnormal.

[0057] In this embodiment, the tracing data of ftrace can be presented through the file system interface, and it can be used without any additional user-level front end. This solution analyzes and processes the tracing data through the file system interface in the statistical summary module, and summarizes the reception (such as: RX, RXBYTES, RXERROR) and transmission (such as: TX, TXBYTES, TXERROR) of the socket messages of each process in the cycle.

[0058] S13. Compare the summary data with the pre-configured conditions. When the summary data does not meet the pre-configured conditions, process it according to the pre-set solution.

[0059] In this embodiment, in order to determine whether the summary data in the interaction process is abnormal, the thresholds of reception (such as RX, RXBYTES, RXERROR) and transmission (such as TX, TXBYTES, TXERROR) can be set for the target application in units of application processes, and pre-configured conditions and processing methods after exceeding the thresholds (alarm, intervention, where the intervention method can be restarting the application, etc.) are generated as pre-set plans. Here, the process is used as the unit, which can cover all threads under the process. If you want finer granularity, you can also consider doing it in units of threads.

[0060] The present disclosure adds tracking point functions for socket functions of data interaction in the tracking framework of the gateway device, and can monitor and track the socket messages flowing through these functions in real time, which greatly enhances the visibility and monitoring ability of the gateway device to the data interaction process. By summarizing and counting the socket messages and comparing them with pre-configured conditions, it is possible to promptly discover abnormal situations in data interaction. When the summarized data does not meet the preset conditions, it is processed according to a pre-set plan, which helps to quickly respond to and solve problems and avoid potential risks and losses.

[0061] See also Figure 3 , Figure 3 The second flow chart of a monitoring method based on a socket in a gateway device provided by the present invention is as follows: Figure 3 As shown, in Figure 1 Based on the embodiment of the monitoring method shown, the monitoring method further includes:

[0062] S21. Enable the tracking point function based on a preset period or when a tracking demand is received, and track the socket message flowing through the socket message sending function and the socket message receiving function.

[0063] In this embodiment, this solution uses on-demand or periodic tracing to enable the trace point function, thereby determining the status of the socket message flowing through the socket function; monitoring the socket message on-demand or periodically can reduce the system load, and the overhead involved is divided into static overhead and runtime overhead, among which: static overhead: A) When the tracing framework (ftrace) is enabled at the kernel level, the kernel image will be slightly increased. Runtime overhead: A) When the trace points are activated, they will add a small amount of CPU overhead to each event. The statistical summary module may also increase the CPU overhead of the processed events and the file system overhead of recording events. Whether the overhead is high enough to interfere with the production application depends on the rate of the event and the number of CPUs. In addition, the scope of event recording can be defined by setting filters, such as: only tracking the trace points in the embodiment of the present invention; B) In addition to the overhead of enabling when using the trace point, there is also the overhead of disabling the trace point to make it available. Disabled trace points become a small number of instructions: for ARM, it is a 4-byte no-operation (nop) instruction. A trace point handler is also added at the end of the function, which slightly increases its text segment size. These overheads are very small and overall the CPU / memory consumption is not high in a single run.

[0064] S22, analyzing the tracked socket messages, and obtaining statistics on the number of received data, the number of sent data, the amount of received data, and the amount of sent data in the socket messages of each process within a preset time period as summary data.

[0065] In this embodiment, the system tracks the socket messages flowing through the gateway device. These socket messages are the basic units of network communication and carry the data transmission tasks between different processes. By tracking these messages, the system can obtain the details of network communication. Then, the system will conduct an in-depth analysis of these tracked socket messages. The content of the analysis includes the number of data received and sent by each process within a preset time period, as well as the sum of the amount of received data and the amount of sent data. These data are important bases for evaluating network communication performance, identifying potential problems and optimizing network configuration. During the statistical process, the system will divide according to the preset time period and summarize the socket messages of each process in each time period. In this way, the network communication situation of each process in different time periods, as well as the trend and changes of the overall network communication, can be more intuitively understood.

[0066] In this embodiment, the system outputs these statistical results as summary data. These data not only include the number of received and sent data of each process within the preset time period, but also include the sum of the amount of received data and the amount of sent data, which provides strong data support for subsequent network communication performance evaluation, problem diagnosis and optimization.

[0067] like Figure 4 As shown, in this embodiment, a method flow chart of determining whether a gateway device is abnormal according to summary data includes the following steps:

[0068] S31, comparing the number of received data and the number of sent data of each process within a preset time period with the preset number of data processed.

[0069] In this embodiment, a preset data processing number is set to determine whether the gateway device is abnormal, that is, the number of socket message packets flowing through the socket message sending function and the socket message receiving function is compared with the preset data processing number to determine whether the gateway device is abnormal.

[0070] S32: When the number of received data and / or the number of sent data exceeds the preset number of data to be processed, a warning is issued, and / or the process that exceeds the preset number of data to be processed is restarted.

[0071] In this embodiment, when the number of socket message packets flowing through the socket message sending function and the socket message receiving function is too high, the gateway device is considered to be abnormal at this time, and the abnormal behavior needs to be handled at this time. A warning can be issued to let the relevant staff or users know and handle it in time, or the corresponding process can be restarted to shut down the work of the process to avoid system jams.

[0072] In this embodiment, since different processes have different numbers of data to be processed, different preset numbers of data to be processed can be configured for different processes. Specifically, the preset number of data to be processed in this solution can be set according to the number of data processed in the past by the process.

[0073] like Figure 5 As shown, in this embodiment, the second flow chart of the method for determining whether the gateway device is abnormal according to the summary data includes the following steps:

[0074] S41. Compare the amount of data received and the amount of data sent by each process within a preset time period with the preset data processing amount.

[0075] In this embodiment, in this embodiment, a preset data processing amount is set to determine whether the gateway device is abnormal, that is, the byte amount of the socket message packet flowing through the socket message sending function and the socket message receiving function is compared with the preset data processing amount to determine whether the gateway device is abnormal.

[0076] S42: When the amount of received data and / or sent data exceeds the preset data processing amount, a warning is issued, and / or the process that exceeds the preset data processing amount is restarted.

[0077] In this embodiment, when the number of bytes of the socket message packets flowing through the socket message sending function and the socket message receiving function is too high, the gateway device is considered to be abnormal at this time, and the abnormal behavior needs to be handled at this time. A warning can be issued to let the relevant staff or users know and handle it in time, or the corresponding process can be restarted to shut down the work of the process to avoid system jams.

[0078] In this embodiment, since different processes have different data processing volumes, different preset data processing volumes can be configured for different processes. Specifically, the preset data processing volume in this solution can be set according to the past data processing volume of the process.

[0079] like Figure 6 As shown, based on the above embodiments, the present invention provides a third flow chart of a monitoring method based on a socket in a gateway device, the method comprising:

[0080] 101. Set the socket receiving and sending packet thresholds for the target application process, as well as the processing method (warning, intervention) after exceeding the threshold;

[0081] 102. Enable the kernel option of the ftrace tracing framework in the Linux kernel. After enabling ftrace, the tracing information will include process / thread information;

[0082] 103. Add / enable tracepoints in the Linux kernel functions sock_sendmsg() and sock_recvmsg(), which contain information such as the number of packets, the amount of bytes in the packet, and the protocol of the socket;

[0083] 104. Enable the tracking point event in the ftrace tracking framework on demand or periodically to track the socket messages flowing through sock_sendmsg() and sock_recvmsg(). After a period of time, stop tracking.

[0084] 105. Perform post-analysis processing on the collected tracking data (in the ring buffer) in the user state, and output the TX and RX data of the socket message of each process within the statistical period;

[0085] 106. According to the pre-configuration, an alarm or intervention (such as restarting the process) is issued for the socket receiving and issuing behaviors that exceed the threshold.

[0086] See also Figure 7 , Figure 7 The present invention provides a monitoring system based on a socket in a gateway device. The monitoring system comprises: a tracking point module 11, a tracker module 12, a statistical summary module 13 and a monitoring module 14.

[0087] In this embodiment, the tracking point module 11 is used to start the tracking framework in the gateway device, and add the tracking point function to the socket function for data interaction through the tracking framework;

[0088] In this embodiment, the tracker module 12 is used to track the socket message flowing through the socket function through the tracking point function;

[0089] In this embodiment, the statistical summary module 13 is used to obtain the summary data of the socket message by statistics;

[0090] In this embodiment, the monitoring module 14 is used to compare the summary data with pre-configured conditions, and when the summary data does not meet the pre-configured conditions, process it according to a pre-set solution.

[0091] In this embodiment, the tracking point module 11 is specifically used to add tracking point functions to the socket message sending function and the socket message receiving function through the tracking framework; the tracking point functions include: functions for obtaining the number of socket messages and the amount of data.

[0092] In this embodiment, the tracker module 12 is specifically used to enable the tracking point function based on a preset period or when a tracking demand is received, and to track the socket message flowing through the socket message sending function and the socket message receiving function;

[0093] In this embodiment, the statistical summary module 13 is specifically used to analyze the tracked socket messages, and obtain the number of received data, the number of sent data, the amount of received data and the amount of sent data in the socket messages of each process within a preset time period as summary data.

[0094] In this embodiment, the monitoring module 14 is specifically used to compare the number of received data and the number of sent data of each process within a preset time period with the preset data processing number; when the number of received data and / or the number of sent data exceeds the preset data processing number, a warning is issued, and / or the process that exceeds the preset data processing amount is restarted.

[0095] In this embodiment, the monitoring module 14 is specifically used to compare the amount of data received and the amount of data sent by each process within a preset time period with the preset data processing amount; when the amount of data received and / or the amount of data sent exceeds the preset data processing amount, a warning is issued, and / or the process that exceeds the preset data processing amount is restarted.

[0096] In this embodiment, the tracking point module 11 is also used to configure different preset data processing numbers for different processes; and configure different preset data processing amounts for different processes.

[0097] like Figure 8 As shown, an embodiment of the present invention provides an electronic device, including a processor 1110, a communication interface 1120, a memory 1130 and a communication bus 1140, wherein the processor 1110, the communication interface 1120, and the memory 1130 communicate with each other through the communication bus 1140;

[0098] Memory 1130, used for storing computer programs;

[0099] The processor 1110 is used to implement any of the above methods when executing the program stored in the memory 1130.

[0100] In the electronic device provided by the embodiment of the present invention, the processor 1110 activates the tracing framework in the gateway device by executing the program stored in the memory 1130, and adds a tracing point function to the socket function for data interaction through the tracing framework; tracks the socket message flowing through the socket function through the tracing point function, and obtains the summary data of the socket message by statistics; compares the summary data with the pre-configured conditions, and when the summary data does not meet the pre-configured conditions, processes it according to the pre-set plan.

[0101] The communication bus 1140 mentioned in the above electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus 1140 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0102] The communication interface 1120 is used for communication between the above electronic device and other devices.

[0103] The memory 1130 may include a random access memory 1130 (RAM), or may include a non-volatile memory 1130 (non-volatile memory), such as at least one disk memory 1130. Optionally, the memory 1130 may also be at least one storage device located away from the processor 1110.

[0104] The above-mentioned processor 1110 can be a general-purpose processor 1110, including a central processing unit 1110 (CPU), a network processor 1110 (NP), etc.; it can also be a digital signal processor 1110 (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components.

[0105] An embodiment of the present invention provides a computer-readable storage medium, which stores one or more programs. The one or more programs can be executed by one or more processors 1110 to implement the method of any of the above embodiments.

[0106] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, a computer, a server or a data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or a data center that includes one or more available media integration. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk Solid State Disk (SSD)), etc.

[0107] Although the present disclosure has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure.

Claims

1. A monitoring method based on a socket in a gateway device, characterized in that: The monitoring method comprises: Opening a tracing framework in the gateway device, and adding a tracing point function to a socket function for data interaction through the tracing framework; Tracking the socket message flowing through the socket function through the tracking point function, and obtaining summary data of the socket message by statistics; The summary data is compared with a pre-configured condition, and when the summary data does not meet the pre-configured condition, it is processed according to a pre-set solution.

2. The monitoring method according to claim 1, characterized in that: The adding of the tracking point function in the socket function for data interaction through the tracking framework includes: A tracking point function is added to a socket message sending function and a socket message receiving function through the tracking framework; the tracking point function includes: a function for obtaining the number of socket messages and the amount of data.

3. The monitoring method according to claim 2, characterized in that: Tracking the socket message flowing through the socket function through the tracking point function and obtaining summary data of the socket message by statistics includes: Enabling the tracking point function based on a preset period or when a tracking demand is received, and tracking the socket message flowing through the socket message sending function and the socket message receiving function; The tracked socket messages are analyzed, and the number of received data, the number of sent data, the amount of received data, and the amount of sent data in the socket messages of each process within a preset time period are statistically obtained as the summary data.

4. The monitoring method according to claim 3, characterized in that: The comparing the summary data with the pre-configured conditions and processing according to a pre-set scheme when the summary data does not meet the pre-configured conditions includes: Compare the number of received data and the number of sent data of each process within a preset time period with the preset number of data processed; When the number of received data and / or the number of sent data exceeds the preset number of data to be processed, a warning is issued, and / or the process that exceeds the preset number of data to be processed is restarted.

5. The monitoring method according to claim 4, characterized in that: The monitoring method further includes: configuring different preset data processing numbers for different processes.

6. The monitoring method according to claim 3, characterized in that: The comparing the summary data with the pre-configured conditions and processing according to a pre-set scheme when the summary data does not meet the pre-configured conditions includes: Compare the amount of data received and sent by each process within a preset time period with the preset data processing amount; When the amount of received data and / or the amount of sent data exceeds the preset data processing amount, a warning is issued, and / or the process that exceeds the preset data processing amount is restarted.

7. The monitoring method according to claim 6, characterized in that: The monitoring method further includes: configuring different preset data processing amounts for different processes.

8. A monitoring system based on a socket in a gateway device, characterized in that: The monitoring system comprises: A tracking point module, used to enable a tracking framework in the gateway device, and to add a tracking point function to a socket function for data interaction through the tracking framework; A tracker module, used for tracking the socket message flowing through the socket function through the tracking point function; A statistical summary module, used for obtaining summary data of the socket message by statistics; The monitoring module is used to compare the summary data with pre-configured conditions and to process the summary data according to a pre-set solution when the summary data does not meet the pre-configured conditions.

9. An electronic device, characterized in that: include: processor; as well as A memory storing computer executable instructions which, when executed, cause the processor to perform the method according to any one of claims 1-7.

10. A computer storage medium, characterized in that: in, The computer storage medium stores one or more programs, and when the one or more programs are executed by a processor, the method of any one of claims 1 to 7 is implemented.