Conversion device, conversion method, and conversion program

The conversion device with multiple cores and a switching management unit addresses the issue of simultaneous packet overflow by staggering table switching times, ensuring accurate and efficient statistical information transmission.

JP7704215B2Active Publication Date: 2025-07-08NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023565791
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-12-08
Publication Date
2025-07-08
Estimated Expiration
2041-12-08

AI Technical Summary

Technical Problem

Existing conversion technologies result in simultaneous output of large volumes of statistical xFlow packets, exceeding the reception capacity of analysis devices and leading to packet loss and reduced analysis accuracy.

Method used

A conversion device with multiple cores and a switching management unit that manages the timing of switching instructions to separate statistical information cache tables across cores, reducing simultaneous packet output by staggering the table switching times.

Benefits of technology

Significantly reduces the amount of packets output simultaneously, preventing packet loss and maintaining analysis accuracy by distributing the switching of statistical information cache tables across conversion cores.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007704215000001
    Figure 0007704215000001
  • Figure 0007704215000002
    Figure 0007704215000002
  • Figure 0007704215000003
    Figure 0007704215000003
Patent Text Reader

Abstract

A conversion device (100) comprises a plurality of conversion cores. The conversion device (100) includes a switching management unit (120) for repeatedly executing processing for transmitting a switching instruction to some of the plurality of conversion cores.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a conversion device, a conversion method, and a conversion program.

Background Art

[0002] Regarding packets obtained from a network using encapsulation technology (hereinafter referred to as encapsulated packets), there is a format conversion technology that analyzes the packet header (Inner / Outer of the capsule) of the input encapsulated packet, calculates statistical information, and generates and transmits statistical xFlow packets. For example, as prior arts related to the format conversion technology, there are Patent Document 1, Non-Patent Document 1, and Non-Patent Document 2.

[0003] In Patent Document 1 (Non-Patent Document 1), for the header samples of encapsulated packets, statistical information is calculated based on the Inner header inside the capsule, and statistical xFlow packets or the like are generated and transmitted to an existing analyzer.

[0004] FIG. 8 is a diagram for explaining Patent Document 1. As shown in FIG. 8, the conversion device 10 of Patent Document 1 includes a separation unit 10a, a decapsulation unit 10b, and a conversion unit 10c. Header samples xFlow of encapsulated packets are input to the conversion device 10 from various NW devices.

[0005] The conversion unit 10c calculates the statistical information of the input encapsulated packet and sums up the statistical information for each flow until the output condition is satisfied. The conversion unit 10c generates a statistical xFlow packet including the statistical information for the flow that satisfies the output condition and transmits it to an external analyzer.

[0006] The output conditions used by the conversion unit 10c are, for example, that the maximum communication-free time has elapsed since the time when the encapsulated packet was last received for each flow, and that the maximum communication time has elapsed since the time when the encapsulated packet was first received.

[0007] Note that the functions of the conversion unit 10c are distributed and deployed across the conversion cores #1 to #N, and the processing can also be executed in parallel. Encapsulated packets of the same flow are allocated to the same conversion core based on information such as 5-tuple.

[0008] Next, Non-Patent Document 2 will be described. FIG. 9 is a diagram for explaining Non-Patent Document 2. The conversion device 11 of Non-Patent Document 2 includes a protocol analysis unit 11a, a grouping unit 11b, and an information shaping unit 11c. The conversion device 11 receives a mirrored encapsulated packet and a header sample xFlow of the encapsulated packet.

[0009] The protocol analysis unit 11a performs protocol analysis of the input encapsulated packet to identify the Inner / Outer / (xFlow) headers.

[0010] The grouping unit 11b groups the encapsulated packets based on the Inner / Outer / (xFlow) headers identified by the protocol analysis unit 11a and the previously prepared conditions.

[0011] The information shaping unit 11c obtains the grouping result of the grouping unit 11b, performs the processing defined for each group, generates statistical xFlow packets, etc., and transmits them to the analysis devices 12A and 12B.

[0012] Here, the conversion unit 10c described in FIG. 8 and the information shaping unit 11c described in FIG. 9 have a function of generating and transmitting a statistical xFlow packet that sums up the statistical information of the input encapsulated packet for each flow and stores the statistical information of the flow that satisfies the output condition. When managing whether or not the output condition is satisfied for each flow, such a function will result in a large processing load.

[0013] Regarding the above function, Non-Patent Document 3 describes a technique of generating and transmitting a statistical xFlow packet using two statistical information cache tables for registering statistical information.

[0014] FIG. 10 is a diagram for explaining Non-Patent Document 3. As shown in FIG. 10, the conversion device 20 of Non-Patent Document 3 has a conversion core 21.

[0015] The conversion core 21 has a registration table 22, an output table 23, a statistical information generation processing unit 24, a table switching monitoring unit 25, and a switching processing unit 26. Initially, a statistical information cache table A is set in the registration table 22, and a statistical information cache table B is set in the output table 23.

[0016] The statistical information generation processing unit 24 executes the statistical information generation processing described below based on the header samples of the encapsulated packets.

[0017] The statistical information generation processing unit 24 identifies a flow based on the header samples of the encapsulated packets.

[0018] The statistical information generation processing unit 24 determines whether to perform a new registration or an update in the statistical information cache table A based on the identification result of the flow. For example, when the statistical information corresponding to the identified flow is already registered in the statistical information cache table A, the statistical information generation processing unit 24 determines to perform an update. On the other hand, when the statistical information corresponding to the identified flow is not registered in the statistical information cache table A, the statistical information generation processing unit 24 determines to perform a new registration.

[0019] The statistical information generation processing unit 24 calculates statistical information from the header samples in the same manner as the methods described in Patent Document 1 and Non-Patent Documents 1 and 2.

[0020] When the statistical information generation processing unit 24 determines to perform an update by the above processing, it updates the statistical information of the corresponding flow registered in the statistical information cache table A. On the other hand, when the statistical information generation processing unit 24 determines to perform a new registration, it registers the statistical information for the flow in the statistical information cache table A.

[0021] The statistical information generation processing unit 24 repeatedly executes the above-described statistical information generation processing.

[0022] The table switching monitoring unit 25 transmits a switching instruction to the switching processing unit 26 at a predetermined time interval.

[0023] When the switching processing unit 26 acquires a switching instruction from the table switching monitoring unit 25, it executes the switching processing described below.

[0024] The switching processing unit 26 initializes the statistical information cache table B set in the output table 23.

[0025] The switching processing unit 26 switches the statistical information cache table A in the registration table 22 and the statistical information cache table B in the output table 23. As a result, the statistical information cache table B is set in the registration table 22, and the statistical information cache table A is set in the output table 23.

[0026] The switching processing unit 26 acquires the statistical information of all flows from the statistical information cache table A. Based on the acquired statistical information, the switching processing unit 26 generates a statistical type xFlow packet and transmits it to the analysis device 12C.

Prior Art Documents

Patent Documents

[0027]

Patent Document 1

Non-Patent Documents

[0028]

Non-Patent Document 1

Non-Patent Document 2

Non-Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0029] In the technology of Non-Patent Document 3 above, the switching processing unit 26 continuously generates and transmits statistical xFlow packets including the statistical information of all flows held in the output table 23.

[0030] Here, if the functions of Non-Patent Document 3 are deployed in the conversion cores #1 to #N like the technology of Patent Document 1 and the processing is executed in parallel, the statistical information cache tables are switched simultaneously in all cores. Then, at the switched timing, the statistical xFlow packets generated in all cores are output to the analysis device in a burst.

[0031] FIG. 11 is a diagram for explaining the problems of the prior art. The horizontal axis of the graph in FIG. 11 corresponds to time, and the vertical axis indicates the packet volume of the output statistical xFlow packets. In the example shown in FIG. 11, at t1, t2, and t3, the switching of the statistical information cache table is performed, and the statistical xFlow packets are output simultaneously from the conversion cores #1 to #N.

[0032] As shown in FIG. 11, when the statistical xFlow packets are output to the analysis device simultaneously, it exceeds the reception capacity of the analysis device, resulting in packet loss. Due to the packet loss, the statistical information is insufficient, and the analysis accuracy of the analysis device decreases.

[0033] The present invention has been made in view of the above, and an object thereof is to provide a conversion device, a conversion method, and a conversion program capable of significantly reducing the amount of packets simultaneously output from the conversion device.

Means for Solving the Problems

[0034] In order to solve the above-described problems and achieve the object, the conversion device includes a plurality of conversion cores, and a switching management unit that repeatedly executes a process of transmitting a switching instruction to some of the plurality of conversion cores. Each of the plurality of conversion cores includes a storage unit that stores two statistical information cache tables separately as a registration table and an output table, a statistical information generation processing unit that generates statistical information for each flow of encapsulated packets and registers the generated statistical information for each flow in the statistical information cache table set in the registration table, and a switching processing unit that, when receiving a switching instruction from the switching management unit, switches the statistical information cache table of the registration table and the statistical information cache table of the output table, generates a statistical xFlow packet including the statistical information registered in the statistical information cache table of the output table, and transmits the generated statistical xFlow packet.

Effects of the Invention

[0035] According to the present invention, the amount of packets simultaneously output from the conversion device can be significantly reduced.

Brief Description of the Drawings

[0036]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

MODE FOR CARRYING OUT THE INVENTION

[0037] Hereinafter, embodiments of the conversion device, conversion method, and conversion program disclosed in the present application will be described in detail with reference to the drawings. Note that the present invention is not limited by this embodiment.

EXAMPLE

[0038] The outline of the processing of the conversion device according to Embodiment 1 will be described. The conversion device distributes the functions of Non-Patent Document 3 to a plurality of conversion cores and executes parallel processing. The conversion device manages, for each conversion core, the timing for switching the statistical information cache table set in the registration table and the statistical information cache table set in the output table throughout the device, and executes the switching of each statistical information cache table of each conversion core with a time difference. In the following description, switching the statistical information cache table set in the registration table and the statistical information cache table set in the output table is referred to as "table switching".

[0039] FIG. 1 is a diagram showing the relationship between the table switching time and the packet volume of the conversion device according to the first embodiment. The horizontal axis of the graph in FIG. 1 corresponds to time, and the vertical axis indicates the packet volume of the output statistical xFlow packets. For example, in the example shown in FIG. 1, at t1, t4, and t7, statistical xFlow packets are output from conversion core #1. At t2, t5, and t8, statistical xFlow packets are output from conversion core #2. At t3, t6, and t9, statistical xFlow packets are output from conversion core #N. N is the total number of conversion cores.

[0040] As shown in FIG. 1, since the statistical xFlow packets generated by the plurality of conversion cores #1 to #N are not output simultaneously, the packet volume output from the conversion device simultaneously can be reduced.

[0041] Next, a configuration example of the conversion device according to the first embodiment will be described. FIG. 2 is a functional block diagram showing the configuration of the conversion device according to the first embodiment. As shown in FIG. 2, this conversion device 100 includes a packet distribution unit 110, a switching management unit 120, and conversion cores #1 to #N. The conversion device 100 receives a mirrored encapsulated packet and a header sample xFlow of the encapsulated packet.

[0042] The packet distribution unit 110 distributes the header samples of the encapsulated packets to the conversion cores #1 to #N based on, for example, the 5-tuple of the Inner / Outer headers of the encapsulated packets. When the packet distribution unit 110 distributes the header samples to the conversion cores #1 to #N, it controls so that, for example, header samples with the same combination of the destination / source addresses of the Inner header and the destination / source addresses of the Outer header are distributed to the same conversion core.

[0043] The packet distribution unit 110 has the function of a load balancer and distributes the header samples to the conversion cores #1 to #N so that the load does not concentrate on the same conversion core.

[0044] Here, when the present invention is implemented in the conversion device 10 described with reference to FIG. 8, the separation unit 10a and the decapsulation unit 10b execute processing on the header sample xFlow of the encapsulated packet, and the resulting header sample is input to the packet distribution unit 110.

[0045] When the present invention is implemented in the conversion device 11 described with reference to FIG. 9, the protocol analysis unit 11a and the grouping unit 11b execute processing on the encapsulated packet and the header sample xFlow of the encapsulated packet, and the resulting header sample is input to the packet distribution unit 110.

[0046] The switching management unit 120 transmits a switching notification in the order of conversion cores #1 to #N every switching notification transmission time interval (T). The conversion cores #1 to #N receive the switching notification every N×T time.

[0047] The conversion core #1 will be described. The description regarding the conversion cores #2 to #N is the same as that of the conversion core #1. The conversion core #1 includes a registration table 50, an output table 51, a statistical information generation processing unit 52, and a switching processing unit 53. Initially, the statistical information cache table A is set in the registration table 50, and the statistical information cache table B is set in the output table 51.

[0048] The statistical information generation processing unit 52 executes the statistical information generation processing described below based on the header sample of the encapsulated packet.

[0049] The statistical information generation processing unit 52 identifies a flow and a group based on the header sample of the encapsulated packet. The flow is identified based on, for example, the 5-tuple of the Inner / Outer header of the encapsulated packet. Note that when no group identifier is assigned, the statistical information generation processing unit 52 only executes flow identification and does not execute group identification.

[0050] The group will be described. For example, the grouping unit 11b described in FIG. 9 groups encapsulated packets based on the Inner / Outer / (xFlow) header identified by the protocol analysis unit 11a and a previously prepared condition, and assigns a group identifier to the encapsulated packets. The statistical information generation processing unit 52 identifies the group of the encapsulated packets based on the group identifier assigned to the encapsulated packets.

[0051] Based on the identification results of the flow and the group, the statistical information generation processing unit 52 determines whether to perform a new registration or an update in the statistical information cache table A. For example, when the statistical information corresponding to the identified flow is already registered in the statistical information cache table A, the statistical information generation processing unit 52 determines to perform an update. On the other hand, when the statistical information corresponding to the identified flow is not registered in the statistical information cache table A, the statistical information generation processing unit 52 determines to perform a new registration.

[0052] The statistical information generation processing unit 52 calculates statistical information from the header samples in the same manner as the methods described in Non-Patent Documents 1 and 2. The statistical information is information such as the number of encapsulated packets and the data volume.

[0053] When the statistical information generation processing unit 52 determines to perform an update by the above processing, it updates the statistical information of the corresponding flow registered in the statistical information cache table A. On the other hand, when the statistical information generation processing unit 52 determines to perform a new registration, it registers the statistical information for the flow in the statistical information cache table A.

[0054] The statistical information generation processing unit 52 repeatedly executes the above statistical information generation processing.

[0055] When the switching processing unit 53 receives a switching instruction from the switching management unit 120, it executes the switching processing described below.

[0056] The switching processing unit 53 initializes the statistical information cache table B set in the output table 51.

[0057] The switching processing unit 53 switches between the statistical information cache table A in the registration table 50 and the statistical information cache table B in the output table 51. As a result, the statistical information cache table B is set in the registration table 50, and the statistical information cache table A is set in the output table 51.

[0058] The switching processing unit 53 acquires statistical information for all flows from the statistical information cache table A, generates a statistical xFlow packet including the acquired statistical information, and transmits it to an external analyzer.

[0059] Incidentally, in the example shown in FIG. 2, the case where each switching processing unit 53 of the conversion cores #1 to #N has a function of generating a statistical xFlow packet including statistical information and transmitting it to an external analyzer has been described, but the present invention is not limited thereto. For example, a common packet generation unit may be arranged outside the conversion cores #1 to #N, and such a packet generation unit may acquire statistical information from the conversion cores #1 to #N, generate a statistical xFlow packet, and transmit it to an external analyzer.

[0060] Next, an example of the processing procedure of the switching management unit 120 according to the first embodiment will be described. FIG. 3 is a flowchart showing the processing procedure of the switching management unit according to the first embodiment. In FIG. 3, t represents the elapsed time from t = 0. n (n = 1 to N) represents the core number for identifying the conversion core. As shown in FIG. 3, the switching management unit 120 of the conversion device 100 sets n = 1 (step S101).

[0061] The switching management unit 120 sets t = 0 and starts monitoring the elapsed time t (step S102). If t ≧ T is not satisfied (step S103, No), the switching management unit 120 returns to step S103 again. On the other hand, if t ≧ T is satisfied (step S103, Yes), the switching management unit 120 transmits a switching notification to the conversion core #n (step S104).

[0062] When n < N (step S105, Yes), the switching management unit 120 sets n = n + 1 (step S106) and proceeds to step S102. On the other hand, when n < N does not hold (step S105, No), the switching management unit 120 sets n = 1 (step S107) and proceeds to step S102.

[0063] Next, the effects of the conversion device 100 according to the first embodiment will be described. When the conversion device 100 executes parallel processing of the conversion cores #1 to #N, it transmits a switching notification in the order of the conversion cores #1 to #N every switching notification transmission time interval (T). As a result, based on the statistical information generated by the plurality of conversion cores #1 to #N, statistical xFlow packets are not output simultaneously, so the amount of packets output simultaneously from the conversion device 100 can be reduced.

Embodiment

[0064] The conversion device according to the second embodiment transmits a switching request from the conversion core to the switching management unit when the traffic surges and the number of flows registered in the registration table exceeds the threshold. When receiving the switching request, the switching management unit changes the switching notification transmission time interval (T).

[0065] FIG. 4 is a functional block diagram showing the configuration of the conversion device according to the second embodiment. As shown in FIG. 4, this conversion device 200 includes a packet distribution unit 110, a switching management unit 210, and conversion cores #1 to #N. The conversion device 200 receives a mirrored encapsulated packet and a header sample xFlow of the encapsulated packet.

[0066] The description of the packet distribution unit 110 is the same as that described in FIG. 2.

[0067] The switching management unit 210 initially sends switching notifications in the order of conversion cores #1 to #N at each switching notification transmission time interval (T). When the switching management unit 210 has not received a switching request from any of the conversion cores, it sets the notification level to "0". While the notification level is "0", the switching management unit 210 calculates the switching notification transmission time interval (T) based on Equation (1). In Equation (1), TA represents the period for sending switching notifications. N represents the number of conversion cores #1 to #N.

[0068] T = TA / N ··· (1)

[0069] When the switching management unit 210 receives a switching request from any of the conversion cores #1 to #N, it updates the notification level to "1". While the notification level is "1", the switching management unit 210 calculates the switching notification transmission time interval (T) based on Equation (2). In Equation (2), the value of α is set in the range of 0 < α < 1.

[0070] T = α × TA / N ··· (2)

[0071] When a predetermined time has elapsed since the switching management unit 210 last received a switching request, it updates the current notification level to "0".

[0072] The conversion core #1 will be described. The descriptions regarding the conversion cores #2 to #N are the same as those of the conversion core #1. The conversion core #1 includes a registration table 50, an output table 51, a statistical information generation processing unit 52, a switching processing unit 53, and a notification unit 54.

[0073] The descriptions of the registration table 50, the output table 51, the statistical information generation processing unit 52, and the switching processing unit 53 are the same as the content described in FIG. 2.

[0074] The notification unit 54 receives count information from the statistical information generation processing unit 52. The statistical information generation processing unit 52 counts the number of flows registered in the statistical information cache table (initially, the statistical information cache table A) set in the registration table 50, and transmits it to the notification unit 54 as count information. Based on the count information, when the number of flows exceeds the threshold value (NF), the notification unit 54 transmits a switching request to the switching management unit 210. For example, the value of 90% of the upper limit of the number of flows that can be registered in the registration table 50 is set for NF. Note that when switching the table, the count information of the number of flows registered in the registration table 50 is set to 0 at the time of table switching.

[0075] Next, the effects of the conversion device 200 according to the second embodiment will be described. When the number of flows registered in the registration table 50 exceeds the threshold value, the conversion device 200 transmits a switching request from the conversion core to the switching management unit 210. When receiving the switching request, the switching management unit 210 changes the switching notification transmission time interval (T) based on Equation (2) to shorten the period for transmitting the switching request to the conversion cores #1 to #N. As a result, even when the traffic suddenly increases, it is possible to avoid a situation where statistical information overflows from the registration table 50.

Example

[0076] When the traffic suddenly increases and the number of flows registered in the registration table exceeds the threshold value, the conversion device according to the third embodiment transmits a switching request from the conversion core to the switching management unit. The switching request includes a core number that identifies the conversion core that is the source of the switching request.

[0077] The switching management unit transmits a switching notification to the conversion cores #1 to #N in order at each switching notification transmission time interval (T) in the same manner as in the first embodiment, and also transmits a switching notification to the conversion core that has transmitted the switching request. The switching management unit transmits the switching notification with a time interval of at least a predetermined guard time so that the output of the statistical xFlow packets from the conversion cores #1 to #N does not overlap.

[0078] FIG. 5 is a diagram for explaining the timing at which the conversion device according to Embodiment 3 transmits a switching notification. The switching management unit of the conversion device transmits a switching notification to conversion core #1 at time t1. If the switching management unit receives a switching request from conversion core #3 at time t2 before the elapse of the switching notification transmission time interval (T) from time t1, the switching management unit transmits the switching notification to conversion core #3.

[0079] The switching management unit transmits a switching notification to conversion core #2 at time t3 when the switching notification transmission time interval (T) has elapsed from time t1. The switching management unit transmits a switching notification to conversion core #3 at time t4 when the switching notification transmission time interval (T) has elapsed from time t3.

[0080] Here, the switching management unit sets a guard time before and after the time when the switching notification is made, and transmits the switching notification with a time interval longer than the guard time. For example, if the switching management unit transmits a switching notification to conversion core #1 at time t1, and time t3 when a switching request is received from conversion core #3 is included in the guard time based on time t1, the switching management unit transmits the switching notification to conversion core #3 after the elapse of such guard time.

[0081] In FIG. 5, the switching management unit similarly sets a guard time for times t2, t3, and t4, and if a switching request is received before the elapse of the guard time in the same manner as the above description, the switching management unit transmits a switching notification to the conversion core that is the source of the switching request immediately after the elapse of the guard time.

[0082] FIG. 6 is a functional block diagram showing the configuration of the conversion device according to Embodiment 3. As shown in FIG. 6, this conversion device 300 includes a packet distributing unit 110, a switching management unit 310, and conversion cores #1 to #N. The conversion device 300 receives a mirrored encapsulated packet and a header sample xFlow of the encapsulated packet.

[0083] The description of the packet distributing unit 110 is the same as that described in FIG. 2.

[0084] The switching management unit 310 transmits a switching notification in the order of conversion cores #1 to #N for each switching notification transmission time interval (T), and transmits a switching notification to the conversion core that has transmitted a switching request while transmitting the switching notification. The switching management unit 311 transmits a switching notification with a time interval of a predetermined guard time or more so that the outputs of the statistical xFlow packets from the conversion cores #1 to #N do not overlap. The description of the switching management unit 310 is the same as the description given in FIG. 5.

[0085] Next, the effects of the conversion device 300 according to the third embodiment will be described. The conversion device 300 transmits a switching notification in the order of conversion cores #1 to #N for each switching notification transmission time interval (T), and transmits a switching notification to the conversion core that has transmitted a switching request while transmitting the switching notification. The conversion device 300 transmits a switching notification with a time interval of a predetermined guard time or more so that the outputs of the statistical xFlow packets from the conversion cores #1 to #N do not overlap. As a result, it is possible to avoid a situation where statistical information overflows from the registration table 50 of a specific conversion core due to a sudden increase in traffic.

[0086] Subsequently, an example of a computer that executes a conversion program will be described. FIG. 7 is a diagram showing an example of a computer that executes a conversion program. The computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0087] Memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to the hard disk drive 1031. The disk drive interface 1040 is connected to the disk drive 1041. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1041. For example, a mouse 1051 and a keyboard 1052 are connected to the serial port interface 1050. For example, a display 1061 is connected to the video adapter 1060.

[0088] Here, the hard disk drive 1031 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. Each piece of information described in the above embodiment is stored, for example, in the hard disk drive 1031 or the memory 1010.

[0089] Also, the conversion program is stored in the hard disk drive 1031 as a program module 1093 in which instructions executed by the computer 1000 are described. Specifically, the program module 1093 in which each process for executing the packet distribution unit 110, the switching management unit 120, and the conversion cores #1 to #N described in the above embodiment is stored in the hard disk drive 1031.

[0090] Also, the data used for the information processing by the conversion program is stored, for example, in the hard disk drive 1031 as program data 1094. Then, the CPU 1020 reads out the program module 1093 and the program data 1094 stored in the hard disk drive 1031 into the RAM 1012 as needed, and executes each of the above-described procedures.

[0091] Note that the program modules 1093 and program data 1094 related to the conversion program are not limited to being stored in the hard disk drive 1031. For example, they may be stored in a removable storage medium and read by the CPU 1020 via a disk drive 1041 or the like. Alternatively, the program modules 1093 and program data 1094 related to the conversion program may be stored in another computer connected via a network such as a LAN or a WAN (Wide Area Network) and read by the CPU 1020 via the network interface 1070.

[0092] As described above, the embodiments to which the invention made by the present inventor is applied have been described. However, the present invention is not limited by the description and the drawings that form a part of the disclosure of the present invention according to this embodiment. That is, all other embodiments, examples, operation techniques, etc. made by those skilled in the art based on this embodiment are included in the scope of the present invention.

Explanation of Reference Numerals

[0093] 50 Registration Table 51 Output Table 52 Statistical Information Generation Processing Unit 53 Switching Processing Unit 54 Notification Unit 100 Conversion Device 110 Packet Distribution Unit 120, 210, 310 Switching Management Unit

Claims

1. A plurality of conversion cores, a switching management unit that repeatedly executes a process of transmitting a switching instruction to some of the plurality of conversion cores, and each of the plurality of conversion cores includes a storage unit that stores two statistical information cache tables separately as a registration table and an output table, a statistical information generation processing unit that generates statistical information for each flow of encapsulated packets and registers the generated statistical information for each flow in the statistical information cache table set in the registration table, when receiving the switching instruction from the switching management unit, switches the statistical information cache table of the registration table and the statistical information cache table of the output table, generates a statistical xFlow packet including the statistical information registered in the statistical information cache table of the output table, and has a switching processing unit that transmits the generated statistical xFlow packet A conversion device characterized by the above.

2. The switching management unit selects one conversion core from the plurality of conversion cores in order at predetermined time intervals, and transmits the switching instruction to the selected conversion core. The conversion device according to Claim 1.

3. Each of the plurality of conversion cores further includes a notification unit that transmits a switching request to the switching management unit when the data amount of the statistical information in the statistical information cache table set in the registration table exceeds a threshold value, The switching management unit further executes a process of shortening the predetermined time interval when receiving the switching request. The conversion device according to Claim 2.

4. When receiving the switching request, the switching management unit further executes a process of transmitting the switching instruction to the conversion core that is the source of the switching request after a time equal to or longer than the guard time from the timing when the previous switching instruction was transmitted. The conversion device according to Claim 3.

5. A storage unit that stores two statistical information cache tables separately as a registration table and an output table, a statistical information generation processing unit that generates statistical information for each flow of encapsulated packets and registers the generated statistical information for each flow in the statistical information cache table set in the registration table, When a switching instruction is received, a switching process is performed between the statistical information cache table of the registration table and the statistical information cache table of the output table, a statistical type xFlow packet including the statistical information registered in the statistical information cache table of the output table is generated, and the generated statistical type xFlow packet is transmitted. A conversion method executed by a conversion device having a plurality of conversion cores, comprising: A switching management step of repeatedly executing a process of transmitting a switching instruction to some of the plurality of conversion cores; A conversion method characterized by including the above.

6. A conversion program for causing a computer to function as the conversion device according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Flow information analysis apparatus, flow information analysis method, and flow information analysis program

    WO2018066228A1

  • Conversion device, conversion method, and conversion program

    WO2021149245A1