NETWORK MONITORING DEVICE, NETWORK MONITORING METHOD, AND NETWORK MONITORING PROGRAM
The network monitoring device addresses the challenge of simultaneous reliable and timely notification of network abnormalities and normal data by using a determination mechanism, aggregation mechanism, and priority control mechanism with adaptive data handling and transmission priorities.
Patent Information
- Application Number
- JP2021149720
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-14
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2041-09-14
AI Technical Summary
Existing network monitoring systems struggle to simultaneously satisfy the requirements of notifying network monitoring results without fail, allowing delayed notifications during normal network conditions, and providing early notification of abnormalities during abnormal conditions, due to bandwidth constraints.
A network monitoring device equipped with a determination mechanism to assess network normalcy, an aggregation mechanism for statistical processing, and a priority control mechanism with separate queues for normal and abnormal data, which adjusts the granularity of data aggregation and transmission priorities based on queue usage and network status.
The solution enables early and reliable notification of network abnormalities while ensuring that normal monitoring data is aggregated and reported with minimal delay, thus meeting all three requirements simultaneously even under bandwidth constraints.
Smart Images

Figure 0007689283000001 
Figure 0007689283000002 
Figure 0007689283000003
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a network monitoring device, a network monitoring method, and a network monitoring program. [Background technology]
[0002] 2. Description of the Related Art In order to grasp the network usage status and the presence or absence of abnormalities, network monitoring systems using various methods are operated. Specific examples of what a network monitoring system monitors include: (1) the usage status of the devices that make up the network (CPU load, memory usage, etc.); (2) the presence or absence of communication and response time in a specific section; (3) the amount of traffic that has passed and the amount of traffic that has been discarded; and (4) information indicating any errors that have occurred. A network monitoring system monitors such information periodically or whenever an abnormality occurs, and based on the observed data, presents graphs or the like and notifies the network administrator.
[0003] In recent years, there has been an increase in communication demands that require streaming and real-time performance, such as voice communication. Furthermore, with the development of various cloud services, the number of applications to be monitored is also increasing. Therefore, in order to grasp the network status in detail, the monitoring interval is shortened and the monitoring unit is refined. Specific examples of refinement of the monitoring unit include "one-minute intervals rather than five-minute intervals" and "traffic volume categorized by source, destination, and application type, etc., rather than the total volume of traffic passing through a network interface." In addition, applications used may differ depending on the time of day, such as during the day and at night, etc. Therefore, the total amount of data generated for monitoring may increase or decrease depending on the time of day.
[0004] On the other hand, a monitoring line is required as a communication line for monitoring the network, and if the bandwidth of the monitoring line is too small compared to the communication demands for monitoring, monitoring data will be discarded, and a situation will arise in which monitoring results cannot be obtained. Figure 1(a) is a graph visualizing this situation. This figure shows how monitoring results are lost during congestion. If the bandwidth of the monitoring line were the maximum amount required for monitoring, the situation shown in Figure 1(a) would not occur, but the costs required for network monitoring would increase. Here, the following three requirements must be met in network monitoring: Requirement 1: Notify network monitoring results without fail. Requirement 2: When the network is in a normal state, it is acceptable for notification of network monitoring results to be delayed. Requirement 3: When the network is in an abnormal state, the network abnormality must be notified at an early stage. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] International Publication No. 2005 / 050931 Brochure Summary of the Invention [Problem to be solved by the invention]
[0006] Conventionally, a priority control technique has been used to stabilize communication traffic (for example, see Patent Document 1). Priority control is a technique for classifying communication requirements into a number of priorities based on a predetermined criterion and communicating in order of priority, and is also known as QoS (Quality of Service). When using the technology disclosed in Patent Document 1, as a specific example, if the priority of traffic indicating an abnormality is set high, the results of monitoring the traffic indicating an abnormality can be notified preferentially. However, there is a possibility that the results of monitoring normal traffic, which is set to a low priority, will be discarded. Therefore, although requirement 3 is satisfied in this example, requirements 1 and 2 are not satisfied, i.e., the above three requirements cannot be satisfied simultaneously.
[0007] An object of the present disclosure is to provide a network monitoring device that simultaneously satisfies the above three requirements. [Means for solving the problem]
[0008] A network monitoring device according to the present disclosure includes: a determination mechanism for determining whether a monitored network is normal or abnormal based on monitoring result data indicating a result of monitoring communications in the monitored network; an aggregation mechanism that performs statistical processing on the monitoring result data to create normal aggregated data when the monitored network is determined to be normal; a priority control mechanism having a normal aggregation queue for storing the normal aggregation data; Equipped with.
[0009] The aggregation mechanism changes the granularity of the normal aggregation data depending on the usage status of the normal aggregation queue.
[0010] the aggregation mechanism performs statistical processing on the monitoring result data to generate anomaly aggregated data when the monitored network is determined to be abnormal; The priority control mechanism includes an anomaly aggregation queue that holds the anomaly aggregate data.
[0011] a priority is set for each of the normal aggregation queue and the abnormal aggregation queue; The priority control mechanism transmits data held in each of the normal aggregation queue and the abnormal aggregation queue in accordance with a set priority.
[0012] A network monitoring method according to the present disclosure includes: A computer determines whether a monitored network is normal or abnormal based on monitoring result data indicating a result of monitoring communications in the monitored network; When the monitored network is determined to be normal, the computer performs statistical processing on the monitoring result data to create normal aggregated data; The computer has a normal aggregation queue for holding the normal aggregation data.
[0013] The network monitoring program according to the present disclosure includes: A determination process for determining whether the monitored network is normal or abnormal based on monitoring result data indicating a result of monitoring communications in the monitored network; an aggregation process for performing statistical processing on the monitoring result data to generate normal aggregated data when the monitored network is determined to be normal; a priority control process having a normal aggregation queue for storing the normal aggregation data; The above is executed by a network monitoring device, which is a computer. Effect of the Invention
[0014] According to the present disclosure, when a monitored network is normal, a statistical process is performed on the monitoring result data to create normal aggregated data, and a normal aggregation queue is provided to hold the normal aggregated data. Therefore, according to the present disclosure, even if an abnormality in a monitored network is preferentially notified early, data held in the normal aggregation queue can be notified later as a monitoring result corresponding to a monitored network that is in a normal state. Therefore, according to the present disclosure, a network monitoring device that simultaneously satisfies the above three requirements can be provided. [Brief description of the drawings]
[0015] [Figure 1]1A and 1B are diagrams for explaining network monitoring results, where (a) is a screen according to the conventional technology, and (b) is a target screen according to the present disclosure. [Diagram 2] 1 is a diagram showing an example of the configuration of a network monitoring system 90 according to a first embodiment. [Diagram 3] 1 is a diagram showing an example of a hardware configuration of a network monitoring device 10 according to a first embodiment. [Figure 4] 4 is a flowchart showing the operation of the network monitoring device 10. [Diagram 5] 3A shows monitoring result data 301; FIG. 3B shows tagged monitoring result data 302; and FIG. 3C shows tabulated result data 303. FIG. [Figure 6] FIG. 13 is a diagram showing an example of a hardware configuration of the network monitoring device 10 according to a modified example of the first embodiment. [Figure 7] FIG. 11 is a diagram showing an example of the configuration of a priority control mechanism 150 according to a second embodiment. [Figure 8] 11A and 11B are diagrams illustrating the operation of a priority control mechanism 150 according to a second embodiment, where FIG. 11A illustrates the operation at the time of initial setting or when there is no congestion, and FIG. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0016] In the description of the embodiments and the drawings, the same elements and corresponding elements are given the same reference numerals. Descriptions of elements given the same reference numerals are omitted or simplified as appropriate. Arrows in the drawings primarily indicate data flow or processing flow. In addition, "mechanism" may be read as "part," "circuit," "step," "procedure," "processing," or "circuitry" as appropriate.
[0017] Embodiment 1 Hereinafter, the present embodiment will be described in detail with reference to the drawings.
[0018] ***Configuration Description*** First, the target screen in this embodiment will be described. Fig. 1(b) is a diagram in which the above-mentioned three requirements are visualized as a graph, and is a diagram showing a screen generated based on data created by the network monitoring device 10. Fig. 1(b) differs from Fig. 1(a) in that (1) abnormal values are displayed immediately even during congestion, and (2) the result of aggregating normal values is displayed with a delay.
[0019] A network monitoring system 90 according to the first embodiment will be described with reference to FIGS. 2 shows an overview of an example of the system configuration of a network monitoring system 90. The network monitoring system 90 is made up of a network monitoring device 10, a monitored network 20, and a management device 30. The devices constituting the network monitoring system 90 may be configured integrally as appropriate. The network monitoring device 10 is connected to both a monitored network 20 and a management device 30 . The monitored network 20 is a target for monitoring by the network monitoring device 10 . As a specific example, the management device 30 is a higher-level monitoring device or a terminal of a network administrator.
[0020] The following describes an overview of the network monitoring device 10. The network monitoring device 10 includes a measurement mechanism 100, a determination mechanism 110, a priority control mechanism 120, an aggregation mechanism 130, and a storage mechanism 140.
[0021] The measurement mechanism 100 includes a measurement result creation unit 101 and a measurement result transmission unit 102. The measurement mechanism 100 is connected to a monitored network 20, grasps communication requirements in the monitored network 20, and monitors network traffic in the monitored network 20. The measurement mechanism 100 may be realized by a known technology such as netflow or SNMP (Simple Network Management Protocol). The measurement mechanism 100 classifies the generated traffic by source, destination, protocol, etc., as in netflow, and measures the total amount of traffic for each classified traffic. Alternatively, the measurement mechanism 100 receives a packet notifying an abnormality from a device in the monitored network 20, as in SNMP trap, as a specific example. Thereafter, the measurement mechanism 100 creates monitoring result data 301 and sends the created monitoring result data 301 to the determination mechanism 110. The monitoring result data 301 indicates the results of monitoring the communications in the monitored network 20.
[0022] The determination mechanism 110 includes a normal / abnormal determination unit 111 and a determination result transmission unit 112 . The determination mechanism 110 determines whether the monitored network 20 is normal or abnormal based on the monitoring result data 301 received from the measurement mechanism 100. The function of the determination mechanism 110 can be realized by a known data processing method. As a specific example, when making a judgment based on the traffic volume, the judgment mechanism 110 may judge that an abnormality exists when the traffic volume exceeds a certain threshold value. Alternatively, the judgment mechanism 110 may judge that an abnormality exists when a specific identification symbol or character string such as FATAL or ERROR exists in a packet. The determination mechanism 110 assigns the determined result to the monitoring result data 301 to create tagged monitoring result data 302, and transmits the created tagged monitoring result data 302 to each of the priority control mechanism 120 and the aggregation mechanism 130.
[0023] The priority control mechanism 120 includes an abnormal aggregation queue 121, an abnormal production queue 122, a normal aggregation queue 123, a normal production queue 124, a transmission control unit 125, and a queue status monitoring unit 126. The priority control mechanism 120 is connected to a communication path to the management device 30, and notifies the management device 30 of the monitoring results by the network monitoring device 10 based on the priority of the monitoring results. The priority control mechanism 120 performs several processes, as follows. (1) The priority control mechanism 120 registers the monitoring result data in a queue corresponding to a priority according to the type of the monitoring result data. The monitoring result data is a general term for the monitoring result data 301, the tagged monitoring result data 302, and the aggregated result data 303. The data registered in each queue may be data corresponding to the monitoring result data. Here, there are at least four types of queues, in order of priority, namely, an abnormality aggregation queue 121, an abnormality production queue 122, a normal aggregation queue 123, and a normal production queue 124. That is, a priority is set for each queue. The abnormality aggregation queue 121 holds data indicating the monitoring result itself indicating an abnormality, which is a monitoring result indicating an abnormality. The abnormality production queue 122 holds data indicating the monitoring result itself indicating an abnormality. The normal aggregation queue 123 holds data indicating the monitoring result itself indicating a normality, which is a monitoring result indicating an aggregated result. The normal production queue 124 holds data indicating the monitoring result itself indicating a normality. The queue is also a general term for each queue that the priority control mechanism 120 has. The data that the priority control mechanism 120 receives from the determination mechanism 110 indicates the monitoring result itself. Therefore, the data is registered in the abnormal result queue 122 or the normal result queue 124. (2) The priority control mechanism 120 transmits the monitoring result data registered in each queue, and the data held by each queue, to the management device 30 according to the priority set for each queue. Here, as a method of transmitting data from each queue according to the priority set for each queue, in the conventional QoS technology, there are, as specific examples, a method of repeatedly transmitting data from the high-priority queue until the high-priority queue becomes empty, or a method of transmitting data by appropriately switching between the high-priority queue and the low-priority queue like a round robin method. A specific example of the latter method is a method of transmitting data from the low-priority queue at a predetermined rate in addition to the high-priority queue. Here, the high-priority queue is a queue with the highest priority among the queues that are not empty. The low-priority queue is a queue that is not empty but is not a high-priority queue. The priority control mechanism 120 may adopt any QoS method. (3) Meanwhile, the priority control mechanism 120 checks the free space of each queue, generates an instruction regarding the aggregation period according to the checked free space, and notifies the aggregation mechanism 130 of the generated instruction. The aggregation period is a period to be aggregated when aggregating the monitoring result data 301, and specifically, is the time span for aggregating data or the period during which data was measured. Specific examples of the content of the instruction include information indicating the absolute value or percentage of the free space of each queue, lengthening or shortening the aggregation period, or setting the aggregation period to a specific period such as 1 minute or 5 minutes. The aggregation period may also be different for each queue.
[0024] The aggregation mechanism 130 includes an aggregate value calculation unit 131, a data storage unit 132, and an aggregate value transmission unit 133. When the monitored network 20 is determined to be normal, the aggregation mechanism 130 performs statistical processing on the monitoring result data to create normal aggregate data, and when the monitored network 20 is determined to be abnormal, the aggregation mechanism 130 performs statistical processing on the monitoring result data to create abnormal aggregate data. The normal aggregation queue 123 holds the normal aggregate data. The abnormal aggregation queue 121 holds the abnormal aggregate data. The aggregation mechanism 130 may change the granularity of the normal aggregate data according to the usage status of the normal aggregation queue 123. That is, the aggregation mechanism 130 may lengthen the aggregation period when the free space of each queue is small, that is, may coarsen the granularity of the data registered in each queue. Also, the aggregation mechanism 130 may shorten the aggregation period when the free space of each queue is large, that is, may fine the granularity of the data registered in each queue. The aggregation mechanism 130 obtains an aggregate value for a certain time range for the monitoring result data 301 having the same source, destination, protocol, etc., in response to an instruction regarding the aggregation period notified by the priority control mechanism 120, and transmits the obtained aggregate value to the priority control mechanism 120. Specific examples of the aggregate value include at least one of the number of measurements, the total value, the average value, the minimum value, the maximum value, and the standard deviation. The aggregation mechanism 130 obtaining an aggregate value for the monitoring result data corresponds to performing statistical processing on the monitoring result data. The priority control mechanism 120 registers the aggregate value obtained by the aggregation mechanism 130 in the abnormal aggregation queue 121 or the normal aggregation queue 123. The aggregation period is determined based on an instruction notified by the priority control mechanism 120. The aggregation mechanism 130 may determine the aggregation period. Notifying the aggregate value for a certain time range corresponds to notifying all network monitoring results for the certain time range. In addition, the aggregation mechanism 130 transmits the monitoring result data 301 or the tagged monitoring result data 302 and the aggregated result data 303 to the storage mechanism 140 . When the aggregation mechanism 130 lengthens the aggregation period in response to an instruction from the priority control mechanism 120 or the like, the aggregation mechanism 130 may obtain a new aggregate value corresponding to a longer period using the aggregate value that has already been obtained for a shorter period.
[0025] The storage mechanism 140 is a database that holds the monitoring results from the measurement mechanism 100 and the aggregation results from the aggregation mechanism 130 for a certain period of time, specifically, that holds the monitoring result data 301 or tagged monitoring result data 302 and the compilation result data 303 for a certain period of time.
[0026] 3 shows an example of a hardware configuration of the network monitoring device 10. The hardware configuration of the network monitoring device 10 will be described with reference to FIG.
[0027] The network monitoring device 10 is a computer. The network monitoring device 10 includes a processor 210. In addition to the processor 210, the network monitoring device 10 includes hardware such as a main memory device 220, an auxiliary memory device 230, a monitoring communication IF (Interface) 240, and a management communication IF 250. The processor 210 is connected to other hardware via a signal line 260 and controls the other hardware.
[0028] The network monitoring device 10 comprises, as functional elements, a measurement mechanism 100, a determination mechanism 110, a priority control mechanism 120, and an aggregation mechanism 130, and these functions are realized by a program 231.
[0029] The processor 210 is a device that executes a program 231. The program 231 is a program that realizes the functions of the measurement mechanism 100, the determination mechanism 110, the priority control mechanism 120, and the aggregation mechanism 130. The processor 210 is an integrated circuit (IC) that performs arithmetic processing. Specific examples of the processor 210 are a central processing unit (CPU), a digital signal processor (DSP), or a graphics processing unit (GPU).
[0030] The main memory 220 is a storage device. Specific examples of the main memory 220 include SRAM (Static Random Access Memory) and DRAM (Dynamic Random Access Memory). The main memory 220 stores the results of calculations performed by the processor 210.
[0031] The auxiliary storage device 230 is a storage device that stores data in a non-volatile manner. A specific example of the auxiliary storage device 230 is a hard disk drive (HDD). The auxiliary storage device 230 may also be a portable recording medium such as a secure digital (SD) memory card, a NAND flash, a flexible disk, an optical disk, a compact disk, a Blu-ray (Blu-ray) disk, or a digital versatile disk (DVD). The auxiliary storage device 230 realizes the storage mechanism 140. The auxiliary storage device 230 also stores a program 231 and application device information 232.
[0032] The monitoring communication IF 240 is a communication port for the processor 210 to acquire traffic information from the monitored network 20. As a specific example, the communication port is composed of a communication chip or a NIC (Network Interface Card). The management communication IF 250 is a communication port for communicating with the management device 30. The monitoring communication IF 240 and the management communication IF 250 may be integrated into one unit.
[0033] The processor 210 loads the program 231 from the auxiliary storage device 230 into the main storage device 220 , reads the program 231 from the main storage device 220 , and executes the processing indicated by the program 231 .
[0034] The program 231 is a program that causes a computer to execute each process, procedure, or step of the measurement mechanism 100, the judgment mechanism 110, the priority control mechanism 120, and the aggregation mechanism 130, each of which is interpreted as a "process," a "procedure," or a "step."
[0035] The program 231 corresponds to a network monitoring program, and may be provided by being stored in a computer-readable recording medium, or may be provided as a program product. The assigned device information 232 is information assigned to the monitoring target of the network monitoring device 10, etc.
[0036] ***Explanation of Operation*** The operation procedure of the network monitoring device 10 corresponds to a network monitoring method.
[0037] 4 is a flowchart showing an example of the operation of the network monitoring device 10. Note that each component of the network monitoring device 10 operates in parallel. First, the operations of the measurement mechanism 100 and the determination mechanism 110 will be described.
[0038] <Step S11> The measurement result creation unit 101 monitors communications within the monitored network 20, and creates monitoring result data 301 indicating the results of the monitoring. The monitoring result data 301 is made up of data indicating the measurement time, the measurement value, and various attributes indicating the measurement target. Here, the measurement time indicates the time when traffic, etc. was measured. The measurement value indicates a value measured by the measurement mechanism 100 such as traffic volume. Specific examples of the various attributes indicating the measurement target include the source, destination, protocol, etc. Note that this disclosure does not particularly restrict the accuracy of the time and value, and the type of attribute value. Also, a known technology for acquiring the data constituting the monitoring result data 301 is a technology such as netflow. The accuracy of the monitoring result data 301 can be improved depending on the specifications of the computer, etc.
[0039] <Step S12> The measurement result transmission unit 102 transmits the monitoring result data 301 created by the measurement result creation unit 101 to the determination mechanism 110 .
[0040] <Step S13> The normal / abnormal determination unit 111 receives the monitoring result data 301, determines whether the monitored network 20 is normal or abnormal based on the received monitoring result data 301, and creates tagged monitoring result data 302 based on the determination result. (b) of Fig. 5 shows a specific example of the format of the tagged monitoring result data 302. The tagged monitoring result data 302 is made up of data indicating the measurement time, normal / abnormal classification, aggregated / raw classification, measurement value, and various attributes indicating the measurement target. Of these, the measurement time, measurement value, and various attributes indicating the measurement target are each duplicates of the data indicated by the monitoring result data 301. The normal / abnormal category indicates the result of the determination made by the normal / abnormal determination unit 111 based on a predetermined criterion. Specific examples of the predetermined criterion include a measurement value being within a predetermined range, or a predetermined identification code such as "ERROR". Note that there are various known methods for the determination method of the normal / abnormal determination unit 111, and the present disclosure does not specify the determination method in particular. The aggregated / raw category indicates whether the measurement values are aggregated or not aggregated, that is, whether the monitoring results of the measurement mechanism 100 are used directly. Note that in step S13, the data received directly from the measurement mechanism 100 is handled, so "raw" is specified across the board.
[0041] <Step S14> The determination result transmission unit 112 transmits the tagged monitoring result data 302 to both the priority control mechanism 120 and the aggregation mechanism 130 .
[0042] Next, a description will be given of the operation of the priority control mechanism 120. The priority control mechanism 120 executes steps S21 to S23 in parallel.
[0043] <Step S21> The priority control mechanism 120 receives tagged monitoring result data 302 from the judgment mechanism 110 or aggregated result data 303 from the aggregation mechanism 130, and registers the received data in one of the queues provided in the priority control mechanism 120 depending on the values of the normal / abnormal classification and aggregated / raw classification indicated by the received data.
[0044] <Step S22> The transmission control unit 125 transmits the data in each queue to the management device 30 as appropriate according to the priority of each queue. The QoS method used by the transmission control unit 125 may be the above-mentioned method or another method.
[0045] <Step S23> The queue status monitoring unit 126 checks the usage status and free space of each queue, and generates an instruction regarding the aggregation period based on the check result. In checking the free space, as a specific example, the queue status monitoring unit 126 checks the absolute value or percentage of the free space. Also, the queue status monitoring unit 126 may set the aggregation period in any way. The queue status monitor 126 notifies the aggregation mechanism 130 of the generated instruction.
[0046] Next, a description will be given of the operation of the aggregation mechanism 130. The aggregation mechanism 130 executes step S31 or step S32, and step S33 in parallel.
[0047] <Step S31> The aggregated value calculation unit 131 receives the tagged monitoring result data 302 transmitted by the determination mechanism 110 in step S14, and accumulates the received tagged monitoring result data 302 in the storage mechanism 140. The aggregated value calculation unit 131 also receives the data transmitted by the priority control mechanism 120 in step S23, and creates aggregated result data 303 by aggregating the tagged monitoring result data 302 for a predetermined period according to the aggregation period indicated by the received data. (c) of Fig. 5 shows a specific example of the format of the aggregated result data 303. The tabulated result data 303 is made up of data indicating an aggregation period, a normal / abnormal category, an aggregated / raw category, various statistics, and various attributes indicating the measurement target. Of these, the normal / abnormal category and the various attributes indicating the measurement target are copies of the data indicated by the tagged monitoring result data 302. The aggregation period consists of the time span, start time, and end time of the data used for aggregation. The time span corresponds to the instruction generated in step S23. The start time is the start time of the period during which the data used to calculate various statistics was measured. The end time is the end time of the period during which the data was measured. In step S32, the aggregate / raw classification is always designated as "aggregated." Furthermore, the tally value calculation unit 131 calculates various statistical values from the measurement values of the tagged monitoring result data 302 to be counted. The various statistical values are the average value, minimum value, maximum value, variance, or number of measurements, etc. The statistical values calculated by the tally value calculation unit 131 differ depending on the implementation or application, and so the statistical values are not particularly specified here.
[0048] <Step S32> The data storage unit 132 registers the compilation result data 303 calculated in step S31 in the storage mechanism 140.
[0049] <Step S33> The tally sending unit 133 sends the tally result data 303 corresponding to the tally period according to the queue usage status to the priority control mechanism 120 .
[0050] ***Explanation of the Effects of the First Embodiment*** According to the network monitoring device 10 of this embodiment, it is possible to control the timing of sending abnormal values or normal values and change the length of the aggregation period depending on the degree of congestion of the priority control mechanism 120. Therefore, according to this embodiment, it is possible to stabilize the communication volume for monitoring by early reporting of abnormal values that should be reported with priority, while aggregating and reporting low priority report items. As a result, the monitoring result as shown in FIG. 1(b) is obtained. That is, according to this embodiment, the administrator of the monitored network 20 can grasp abnormal values early even if the line bandwidth for monitoring is tight, and can grasp the aggregated normal values, although there is some delay. Therefore, according to this embodiment, the above three requirements can be met at the same time.
[0051] ***Other configurations*** <Variation 1> FIG. 6 shows an example of the hardware configuration of the network monitoring device 10 according to this modified example. The network monitoring device 10 includes a processing circuit 280 in place of the processor 210 , the processor 210 and a main memory device 220 , the processor 210 and an auxiliary memory device 230 , or the processor 210 , the main memory device 220 , and the auxiliary memory device 230 . The processing circuit 280 is hardware that realizes at least a part of each unit included in the network monitoring device 10 . The processing circuitry 280 may be dedicated hardware, or may be a processor that executes programs stored in the main memory 220 .
[0052] When processing circuitry 280 is dedicated hardware, processing circuitry 280 may be, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof. The network monitoring device 10 may include a plurality of processing circuits that replace the processing circuit 280. The plurality of processing circuits share the role of the processing circuit 280.
[0053] In the network monitoring device 10, some of the functions may be realized by dedicated hardware, and the remaining functions may be realized by software or firmware.
[0054] Processing circuitry 280 may illustratively be implemented in hardware, software, firmware, or a combination thereof. The processor 210, the main memory device 220, the auxiliary memory device 230, and the processing circuit 280 are collectively referred to as the “processing circuitry.” In other words, the functions of the functional components of the network monitoring device 10 are realized by the processing circuitry. The network monitoring device 10 according to other embodiments may also have a configuration similar to this modified example.
[0055] Embodiment 2 The following mainly describes the differences from the above-described embodiment with reference to the drawings.
[0056] ***Configuration Description*** A network monitoring device 10 according to the second embodiment will be described with reference to Fig. 7 and Fig. 8. The network monitoring device 10 includes a priority control mechanism 150 instead of the priority control mechanism 120. Everything except the priority control mechanism 150 is the same as described in the first embodiment.
[0057] 7 shows an example of the configuration of the priority control mechanism 150. The priority control mechanism 150 corresponds to a mechanism in which some of the components of the priority control mechanism 120 according to the first embodiment have been added or modified. Instead of the four queues described in the first embodiment, the priority control mechanism 150 has a queue group 151 consisting of any number of queues, each of which has a priority set. Here, the highest priority queue is the queue to which the highest priority is set, and the lowest priority queue is the queue to which the lowest priority is set. The queue group 151 is also called a priority order queue group. The priority control mechanism 150 also has a distribution unit 152 as an additional element. These functions will be explained in the description of the operation below. Note that a queue in which normal aggregated data is registered may be called a normal aggregated queue, and a queue in which abnormal aggregated data is registered may be called an abnormal aggregated queue. The program 231 according to this embodiment realizes the functions of the priority control mechanism 150 in place of the priority control mechanism 120 .
[0058] ***Explanation of Operation*** 8 is a diagram for explaining the operation of the priority control mechanism 150. The operation of the priority control mechanism 150 will be explained with reference to this diagram. Note that, among the operations of the priority control mechanism 150, the operation of receiving data from the determination mechanism 110 or the aggregation mechanism 130 and the operation of transmitting data to the management device 30 are similar to the operations of the priority control mechanism 120.
[0059] Fig. 8(a) shows the operation of the priority control mechanism 150 at the time of initial setting or at the time of non-congestion. At this time, as shown in Fig. 8(a), various data received by the priority control mechanism 150 is registered in one of the queues in the queue group 151 by the distribution unit 152 based on the initial setting. Note that the process of the priority control mechanism 150 shown in Fig. 8(a) is substantially equivalent to the process shown in step S21 in the first embodiment.
[0060] The queue status monitor 126 monitors the usage status of each queue in the queue group 151, and notifies the aggregation mechanism 130 of the monitoring results, and also notifies the distribution unit 152 of the monitoring results.
[0061] The allocating unit 152 switches the allocation destination of the monitoring result data as shown in FIG. 8(b) according to the congestion state of each queue in the queue group 151. As a specific example, in the initial setting, the sorting unit 152 registers only data whose normal / abnormal category is "abnormal" and whose aggregated / raw category is "aggregated" in the top priority queue, among the tally result data 303. At this time, if the usage rate of the top priority queue is relatively high, such as 70% or more, the sorting unit 152 may register the data in the second priority queue. The second priority queue is the queue with the second highest priority. As another specific example, the distribution unit 152 may create a temporary queue as long as there is spare computer resources, and distribute data to the created queue, instead of distributing data to an existing queue as described above. In general, there are various methods for measuring the resource status of a computer, and various measurement methods can be combined depending on the programming method. In any case, this example is realized by a known method. In addition, when the usage rate of the highest priority queue is relatively low, such as 30% or less, the allocation unit 152 may, in the initial setting, allocate to the highest priority queue also data that would be allocated to the second priority queue if the usage rate of the highest priority queue is not relatively low.
[0062] ***Explanation of the Effects of the Second Embodiment*** As described above, according to the network monitoring device 10 equipped with the priority control mechanism 150 according to the second embodiment, it is possible to obtain the same effects as those of the first embodiment, and to use queues flexibly. Therefore, according to this embodiment, it is possible to notify data with high priority earlier, and also possible to notify more data with high priority.
[0063] ***Other embodiments*** The above-described embodiments may be freely combined, or any of the components in each embodiment may be modified, or any of the components in each embodiment may be omitted. Moreover, the embodiments are not limited to those shown in the first and second embodiments, and various modifications are possible as necessary. The procedures explained using the flowcharts and the like may be modified as appropriate. [Explanation of symbols]
[0064] 10 network monitoring device, 20 monitored network, 30 management device, 90 network monitoring system, 100 measurement mechanism, 101 measurement result creation unit, 102 measurement result transmission unit, 110 judgment mechanism, 111 normal / abnormal judgment unit, 112 judgment result transmission unit, 120 priority control mechanism, 121 abnormal aggregation queue, 122 abnormal production queue, 123 normal aggregation queue, 124 normal production queue, 125 transmission control unit, 126 queue status monitoring unit, 130 aggregation mechanism, 131 aggregate value calculation unit, 132 data storage unit, 133 aggregate value transmission unit, 140 storage mechanism, 150 priority control mechanism, 151 queue group, 152 distribution unit, 210 processor, 220 main memory device, 230 auxiliary memory device, 231 program, 232 given device information, 240 monitoring communication IF, 250 Management communication IF, 260 signal line, 280 processing circuit, 301 monitoring result data, 302 tagged monitoring result data, 303 compiled result data.
Claims
1. a determination mechanism for determining whether a monitored network is normal or abnormal based on monitoring result data indicating a result of monitoring communications in the monitored network; an aggregation mechanism that performs statistical processing on the monitoring result data to create normal aggregated data when the monitored network is determined to be normal; a priority control mechanism having a normal aggregation queue for storing the normal aggregation data; A network monitoring device comprising: the aggregation mechanism performs statistical processing on the monitoring result data to generate anomaly aggregated data when the monitored network is determined to be abnormal; the priority control mechanism includes an anomaly aggregation queue for storing the anomaly aggregate data; a priority is set for each of the normal aggregation queue and the abnormal aggregation queue; The priority control mechanism is a network monitoring device that transmits data held in each of the normal aggregation queue and the abnormal aggregation queue according to a set priority.
2. The network monitoring device according to claim 1 , wherein the aggregation mechanism changes a granularity of the normal aggregation data depending on a usage status of the normal aggregation queue.
3. A computer determines whether a monitored network is normal or abnormal based on monitoring result data indicating a result of monitoring communications in the monitored network; When the monitored network is determined to be normal, the computer performs statistical processing on the monitoring result data to create normal aggregated data; A network monitoring method, wherein the computer has a normal aggregation queue for holding the normal aggregation data, when the monitored network is determined to be abnormal, the computer performs statistical processing on the monitoring result data to create abnormality aggregate data; The computer includes an anomaly aggregation queue for storing the anomaly aggregation data, a priority is set for each of the normal aggregation queue and the abnormal aggregation queue; The network monitoring method, wherein the computer transmits data held in each of the normal aggregation queue and the abnormal aggregation queue according to set priorities.
4. A determination process for determining whether the monitored network is normal or abnormal based on monitoring result data indicating a result of monitoring communications in the monitored network; an aggregation process for performing statistical processing on the monitoring result data to generate normal aggregated data when the monitored network is determined to be normal; a priority control process having a normal aggregation queue for storing the normal aggregation data; A network monitoring program for causing a network monitoring device, which is a computer, to execute the above. In the aggregation process, when the monitored network is determined to be abnormal, statistical processing is performed on the monitoring result data to generate abnormality aggregated data; The priority control process includes an abnormality aggregation queue for storing the abnormal aggregate data, a priority is set for each of the normal aggregation queue and the abnormal aggregation queue; The priority control process is a network monitoring program that transmits data held in each of the normal aggregation queue and the abnormal aggregation queue according to a set priority.
Citation Information
Patent Citations
Packet transfer control unit
JP2006148778A
Monitoring server, and network monitoring method
JP2010086095A
Packet relay device and packet relay method
JP2021093773A
System and method for observing and controlling a programmable network using a remote network manager
US20150113132A1
Relay device, band control method, band control device, band control program, and computer-readable medium containing the band control program
WO2005050931A1