Traffic statistics information acquisition system and method

The system efficiently detects short-term traffic fluctuations and monitors networks using a small amount of computing resources by employing data collection devices and a database system, addressing the inefficiencies of existing technologies.

JP7779393B2Active Publication Date: 2025-12-03NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024533400
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-07-13
Publication Date
2025-12-03
Estimated Expiration
2042-07-13

AI Technical Summary

Technical Problem

Existing network traffic analysis technologies face challenges in detecting short-term traffic fluctuations efficiently while requiring significant computational resources and costs, especially in high-rate networks.

Method used

A system comprising multiple data collection devices that analyze packets at regular intervals, detect short-term fluctuations, and generate traffic fluctuation notifications, coupled with a data accumulation device that builds a database for long-term traffic monitoring using a small amount of computing resources.

Benefits of technology

Enables efficient detection of short-term traffic fluctuations and comprehensive network monitoring with reduced computational and financial burdens.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007779393000001
    Figure 0007779393000001
  • Figure 0007779393000002
    Figure 0007779393000002
  • Figure 0007779393000003
    Figure 0007779393000003
Patent Text Reader

Abstract

This traffic statistics information acquisition system comprises: a plurality of data collection devices (1) that analyze packets flowing over a network (3), generate traffic statistics information for each of fixed aggregation periods, and generate traffic fluctuation notification information when traffic fluctuation is detected; and a data accumulation device (2) that builds a database on the basis of the traffic statistics information generated by the plurality of data collection devices (1) and the traffic fluctuation notification information.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technique for acquiring network traffic statistics information. [Background technology]

[0002] In order to understand the communication status of a network, it is common to acquire packets flowing through the network and information about those packets. In particular, it is common to collect traffic information in units of flows (groups of packets with common attributes) called xflows, and visualize the collected information using a device called a collector (see Non-Patent Document 1).

[0003] Furthermore, to obtain more detailed traffic information than xflow, it is common to use a filtering technology called PI (Packet Inspection), which analyzes all packets (see Non-Patent Document 2).

[0004] In a group of technologies known as xflow, flow analysis is often performed using sampled data, as disclosed in Non-Patent Document 1. Figure 7 illustrates the sampling operation of Netflow, a type of xflow. Netflow determines which packets are to be counted and which packets are to be discarded at a certain rate among packets 100 flowing through a network device, and generates statistical information by counting the sampled packets in an information collection device 101. Such xflow technologies, typified by Netflow, have advantages such as the ability to estimate overall traffic conditions and the fact that they can be implemented relatively inexpensively due to the small amount of computational resources required for counting. However, these technologies have the problem of difficulty in analyzing short-term traffic fluctuations, especially in high-rate networks.

[0005] On the other hand, analysis techniques using PI analyze each input packet one by one, which allows for the analysis of short-term traffic fluctuations, but the output results are very detailed and voluminous. Furthermore, advanced analysis equipment is generally very expensive. For this reason, deploying multiple PI devices to analyze the entire network has been extremely difficult in reality, both in terms of computational resources and costs. [Prior art documents] [Non-patent literature]

[0006] [Non-Patent Document 1] “InMon Corporation's sFlow:A Method for Monitoring Traffic in Switched and Routed Networks”,IETF Network Working Group,Request for Comments 3176,2001,<https: / / datatracker.ietf.org / doc / html / rfc3176> [Non-patent document 2] Argha Ghosh,Dr.A.Senthilrajan,“Research on Packet Inspection Techniques”,INTERNATIONAL JOURNAL OF SCIENTIFIC & TECHNOLOGY RESEARCH,vol.8,ISSUE 11,2019 Summary of the Invention [Problem to be solved by the invention]

[0007] The present invention has been made to solve the above-mentioned problems, and aims to provide a traffic statistics information acquisition system and method that can detect short-term traffic fluctuations and efficiently monitor a network using a small amount of computing resources. [Means for solving the problem]

[0008] The traffic statistics information acquisition system of the present invention comprises a plurality of data collection devices arranged at a plurality of collection points on a network, configured to analyze packets flowing on the network to generate traffic statistics information at regular aggregation intervals and to generate traffic fluctuation notification information when a traffic fluctuation is detected, and a data accumulation device configured to build a database based on the traffic statistics information and traffic fluctuation notification information generated by the plurality of data collection devices. the data collection device includes a first receiving unit configured to receive packets from a network; a packet analysis unit configured to analyze the packets received by the first receiving unit; a matching function unit configured to identify whether the received packets belong to a flow for which data collection is to be performed based on the analysis result by the packet analysis unit; a statistical information acquisition unit configured to acquire, for each flow, traffic statistical information of packets determined by the matching function unit to belong to a flow for which data collection is to be performed; an aggregation function unit configured to aggregate the traffic statistical information acquired by the statistical information acquisition unit for each flow and for each aggregation period; a short-term fluctuation detection unit configured to generate traffic fluctuation notification information when a traffic fluctuation is detected based on the traffic statistical information acquired by the statistical information acquisition unit; and a transmission unit configured to transmit the traffic statistical information aggregated for each flow and the traffic fluctuation notification information to the data collection device. It is characterized by the following. [Effects of the Invention]

[0009] According to the present invention, a plurality of data collection devices are installed on a network to compile traffic statistical information and detect short-term traffic fluctuations, and the data collection device builds a database based on the traffic statistical information and traffic fluctuation notification information generated by the plurality of data collection devices. As a result, the present invention makes it possible to detect short-term traffic fluctuations while efficiently monitoring the network using a small amount of computing resources. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a block diagram showing the configuration of a traffic statistics information acquisition system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing the configuration of a data collection device according to an embodiment of the present invention. [Figure 3] FIG. 3 is a flowchart illustrating the operation of the data collection device according to the embodiment of the present invention. [Figure 4] FIG. 4 is a block diagram showing the configuration of a data accumulation device according to an embodiment of the present invention. [Figure 5] FIG. 5 is a flowchart illustrating the operation of the data accumulation device according to the embodiment of the present invention. [Figure 6]FIG. 6 is a block diagram showing an example of the configuration of a computer that realizes the data collection device and the data accumulation device according to the embodiment of the present invention. [Figure 7] FIG. 7 is a diagram illustrating the sampling operation of Netflow. DETAILED DESCRIPTION OF THE INVENTION

[0011] [Example] An embodiment of the present invention will now be described with reference to the drawings. Figure 1 is a block diagram showing the configuration of a traffic statistics information acquisition system according to an embodiment of the present invention. The traffic statistics information acquisition system comprises a plurality of data collection devices 1, which are arranged at a plurality of collection points on a network 3, and which analyze packets flowing on the network 3 to generate traffic statistics information at regular aggregation intervals and generate traffic fluctuation notification information when a traffic fluctuation is detected, and a data collection device 2 which builds a database based on the traffic statistics information and traffic fluctuation notification information generated by the plurality of data collection devices 1.

[0012] The data collection device 1 is placed at each of a plurality of collection points on the network 3, and analyzes packets flowing through the network 3. Figure 2 is a block diagram showing the configuration of the data collection device 1. The data collection device 1 is composed of a packet receiving unit 10, a packet analyzing unit 11, a matching function unit 12, a statistical information acquiring unit 13, a counting function unit 14, a short-term fluctuation detecting unit 15, and a transmitting unit 16.

[0013] 3 is a flowchart illustrating the operation of the data collection device 1. The packet receiving unit 10 receives packets from the connected network (step S100 in FIG. 3). The packet analysis unit 11 analyzes the header of the packet received by the packet reception unit 10 and extracts field information from the header (step S101 in FIG. 3).

[0014] The matching function unit 12 identifies whether the packet received by the packet receiving unit 10 belongs to a flow for which data collection is to be performed, based on the field information of the header extracted by the packet analyzing unit 11 (step S102 in FIG. 3).

[0015] Flow information of data collection targets is registered in advance in the matching function unit 12. For example, some combinations of information such as source MAC (Media Access Control) address, destination MAC address, source IP (Internet Protocol) address, destination IP address, source port number, destination port number, protocol type, and VLAN ID (Virtual Local Area Network IDentifier) ​​are registered in the matching function unit 12 as flow information of data collection targets. When the flow information of a received packet matches the flow information registered in advance, the matching function unit 12 determines that the received packet belongs to the flow of data collection targets.

[0016] The statistical information acquisition unit 13 acquires traffic statistical information for each flow of packets determined by the matching function unit 12 to be a flow for which data collection is to be performed (step S103 in FIG. 3). The traffic statistical information includes the number of packets, packet length, etc. Packets determined not to be a flow for which data collection is to be performed are discarded (step S104 in FIG. 3).

[0017] The aggregation function unit 14 aggregates the traffic statistical information acquired by the statistical information acquisition unit 13 for each flow (step S105 in FIG. 3). The aggregation function unit 14 aggregates the traffic statistical information for each flow and for each fixed aggregation period, and when it determines that the aggregation period has elapsed (YES in step S106 in FIG. 3), it transmits the aggregated traffic statistical information to the data accumulation device 2 via the transmitter 16 (step S107 in FIG. 3). At this time, the aggregation function unit 14 adds a flow ID for uniquely identifying the flow to the traffic statistical information and transmits it. Then, the aggregation function unit 14 resets the aggregated traffic statistical information to 0 and also resets the count value of the timer that measures the aggregation period to 0 (step S108 in FIG. 3).

[0018] Meanwhile, the short-term fluctuation detection unit 15 calculates the difference between the latest traffic statistical information acquired by the statistical information acquisition unit 13 and the immediately preceding traffic statistical information (traffic statistical information acquired from the previously received packet) for each flow (step S109 in FIG. 3). This makes it possible to calculate the degree of increase in traffic statistical information over a short period of time. If the latest traffic statistical information has increased significantly and the difference between the latest traffic statistical information and the immediately preceding traffic statistical information exceeds a predetermined threshold (YES in step S110 in FIG. 3), the short-term fluctuation detection unit 15 determines that a short-term traffic fluctuation has occurred and transmits traffic fluctuation notification information to the data accumulation device 2 via the transmission unit 16 (step S111 in FIG. 3). At this time, the short-term fluctuation detection unit 15 adds the ID of the flow for which the difference between the latest traffic statistical information and the immediately preceding traffic statistical information exceeds the threshold to the traffic fluctuation notification information and transmits it.

[0019] After completing the processes of steps S100 to S111, the data collecting device 1 waits to receive the next packet (step S112 in FIG. 3).

[0020] As described above, the data collection device 1 of this embodiment is configured to perform packet analysis and addition / subtraction of traffic statistical information, and does not require a large-capacity database or advanced functions, so it can be realized using small amounts of computing resources and hardware without advanced server functions or expensive server resources.

[0021] 4 is a block diagram showing the configuration of the data accumulating device 2. The data accumulating device 2 is made up of a receiving unit 20, an information classifying unit 21, a database (DB) 22, and an application function unit 23.

[0022] 5 is a flowchart illustrating the operation of the data collection device 2. The receiving unit 20 receives the traffic statistical information and traffic fluctuation notification information transmitted from the data collection device 1 (step S200 in FIG. 5).

[0023] The information classification unit 21 classifies the traffic statistical information and traffic fluctuation notification information received by the receiving unit 20 by flow (step S201 in FIG. 5). As described above, the traffic statistical information and traffic fluctuation notification information are assigned flow IDs, so it is possible to classify the information based on the flow IDs.

[0024] The information classification unit 21 additionally registers the classified information in the DB 22 (step S202 in FIG. 5). At this time, the information classification unit 21 additionally registers the classified information in the DB for each corresponding flow, and also in the DB corresponding to the entire network. In this way, the application function unit 23 can read and use the traffic statistical information and traffic fluctuation notification information registered in the DB 22. Note that the present invention does not limit the application function unit 23 that uses the information, and any application function unit 23 can be implemented in the data accumulation device 2 or an external device.

[0025] The data aggregator 2 of this embodiment does not require a packet analysis function because it receives as input the information generated by the data collector 1. Furthermore, the traffic statistical information sent from the data collector 1 is an aggregate value for a certain period of time that is assumed to be compiled into a database by the data aggregator 2. Therefore, the data aggregator 2 does not need to store the received information for aggregation, and can build a database that shows the communication status of the network simply by sequentially adding the received information to the database.

[0026] As described above, in this embodiment, short-term traffic fluctuations are captured by data collection device 1, and a database representing the long-term behavior of overall traffic is constructed by data collection device 2, allowing data collection device 1 and data collection device 2 to handle only data for the required time intervals, thereby achieving efficient network monitoring.

[0027] Although an example of the traffic statistics information acquisition system of the present invention has been described above, the present invention is not limited to the embodiment, and the configuration can be changed within the scope of the present invention.

[0028] The data collection device 1 and data accumulation device 2 described in this embodiment can each be realized by a computer equipped with a CPU (Central Processing Unit), a storage device, and an interface, and a program that controls these hardware resources. An example of the configuration of this computer is shown in Figure 6.

[0029] The computer includes a CPU 200, a storage device 201, and an interface device (I / F) 202. A communication circuit for connecting to the network 3 is connected to each I / F 102 of the data collection device 1 and the data collection device 2. In such a computer, a program for implementing the traffic statistics information acquisition method of the present invention is stored in the storage device 201. The CPU 200 of each of the data collection device 1 and the data collection device 2 executes the processing described in this embodiment in accordance with the program stored in the storage device 201. At least a part of the data collection device 1 and the data collection device 2 may be implemented by hardware.

[0030] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.

[0031] (Supplementary Note 1) The traffic statistics information acquisition system of the present invention comprises a plurality of data collection devices arranged at a plurality of collection points on a network, configured to analyze packets flowing on the network to generate traffic statistics information at regular aggregation intervals and to generate traffic fluctuation notification information when a traffic fluctuation is detected, and a data accumulation device configured to build a database based on the traffic statistics information and traffic fluctuation notification information generated by the plurality of data collection devices.

[0032] (Supplementary Note 2) In the traffic statistics information acquisition system described in Supplementary Note 1, the data collection device includes: a first receiving unit configured to receive packets from a network; a packet analysis unit configured to analyze the packets received by the first receiving unit; a matching function unit configured to identify whether the received packets belong to a flow for which data collection is to be performed based on the analysis result by the packet analysis unit; a statistical information acquisition unit configured to acquire, for each flow, traffic statistical information of packets determined by the matching function unit to be a flow for which data collection is to be performed; an aggregation function unit configured to aggregate the traffic statistical information acquired by the statistical information acquisition unit for each flow and for each aggregation period; a short-term fluctuation detection unit configured to generate traffic fluctuation notification information when a traffic fluctuation is detected based on the traffic statistical information acquired by the statistical information acquisition unit; and a transmission unit configured to transmit the traffic statistical information aggregated for each flow and the traffic fluctuation notification information to the data collection device.

[0033] (Appendix 3) In the traffic statistical information acquisition system described in Appendix 2, the short-term fluctuation detection unit calculates the difference between the latest traffic statistical information acquired by the statistical information acquisition unit and the immediately preceding traffic statistical information for each flow, and determines that a traffic fluctuation has occurred when the calculated difference exceeds a predetermined threshold.

[0034] (Supplementary Note 4) In the traffic statistical information acquisition system described in Supplementary Note 2 or 3, the data collection device includes a second receiving unit configured to receive the traffic statistical information and traffic fluctuation notification information transmitted from the data collection device, and an information classification unit configured to classify the traffic statistical information and traffic fluctuation notification information received by the second receiving unit by flow, and to additionally register the classified information in the database for the corresponding flow.

[0035] (Appendix 5) The traffic statistical information acquisition method of the present invention includes a first step in which a data collection device at each of a plurality of collection points on a network analyzes packets flowing on the network to generate traffic statistical information at regular aggregation intervals, and generates traffic fluctuation notification information when a traffic fluctuation is detected, and a second step in which the data collection device constructs a database based on the traffic statistical information and traffic fluctuation notification information obtained from the plurality of collection points.

[0036] (Appendix 6) In the traffic statistical information acquisition method described in Appendix 5, the first step includes a third step of receiving packets from a network, a fourth step of analyzing the packets received in the third step, a fifth step of identifying whether the received packets belong to a flow for which data collection is to be performed based on the analysis result of the fourth step, a sixth step of acquiring traffic statistical information for each flow of packets determined to belong to a flow for which data collection is to be performed in the fifth step, a seventh step of aggregating the traffic statistical information acquired in the sixth step for each flow and for each aggregation period, an eighth step of generating traffic fluctuation notification information when a traffic fluctuation is detected based on the traffic statistical information acquired in the sixth step, and a ninth step of transmitting the traffic statistical information and the traffic fluctuation notification information aggregated for each flow to the data accumulation device.

[0037] (Appendix 7) In the traffic statistics information acquisition method described in Appendix 6, the eighth step includes a step of calculating the difference between the latest traffic statistics information acquired in the sixth step and the immediately preceding traffic statistics information for each flow, and determining that a traffic fluctuation is occurring if the calculated difference exceeds a predetermined threshold.

[0038] (Appendix 8) In the traffic statistical information acquisition method described in Appendix 6 or 7, the second step includes a tenth step of receiving the traffic statistical information and traffic fluctuation notification information transmitted from the data collection device, and an eleventh step of classifying the traffic statistical information and traffic fluctuation notification information received in the tenth step by flow and additionally registering the classified information in the database for the corresponding flow. [Industrial Applicability]

[0039] The present invention can be applied to a technology for monitoring a network. [Explanation of symbols]

[0040] 1...data collection device, 2...data accumulation device, 3...network, 10...packet receiving unit, 11...packet analysis unit, 12...matching function unit, 13...statistical information acquisition unit, 14...aggregation function unit, 15...short-term fluctuation detection unit, 16...transmitting unit, 20...receiving unit, 21...information classification unit, 22...database, 23...application function unit.

Claims

1. a plurality of data collection devices arranged at a plurality of collection points on a network, each configured to analyze packets flowing on the network to generate traffic statistical information at a fixed collection period, and to generate traffic fluctuation notification information when a traffic fluctuation is detected; a data collection device configured to build a database based on the traffic statistical information and traffic fluctuation notification information generated by the plurality of data collection devices, The data collection device a first receiver configured to receive packets from a network; a packet analysis unit configured to analyze packets received by the first receiving unit; a matching function unit configured to identify whether a received packet belongs to a flow for which data collection is to be performed, based on the analysis result by the packet analysis unit; a statistical information acquisition unit configured to acquire, for each flow, traffic statistical information of packets determined by the matching function unit to be a flow to be subjected to data collection; an aggregation function unit configured to aggregate the traffic statistical information acquired by the statistical information acquisition unit for each flow and for each aggregation period; a short-term fluctuation detection unit configured to generate traffic fluctuation notification information when a traffic fluctuation is detected based on the traffic statistical information acquired by the statistical information acquisition unit; a transmission unit configured to transmit the traffic statistical information collected for each flow and the traffic fluctuation notification information to the data collection device.

2. 2. The traffic statistics information acquisition system according to claim 1, The short-term fluctuation detection unit calculates the difference between the latest traffic statistical information acquired by the statistical information acquisition unit and the immediately preceding traffic statistical information for each flow, and determines that a traffic fluctuation is occurring if the calculated difference exceeds a predetermined threshold.

3. 3. The traffic statistics information acquisition system according to claim 1, The data collection device a second receiving unit configured to receive traffic statistical information and traffic fluctuation notification information transmitted from the data collecting device; and an information classification unit configured to classify the traffic statistical information and traffic fluctuation notification information received by the second receiving unit by flow and to additionally register the classified information in the database for the corresponding flow.

4. a first step in which a data collection device at each of a plurality of collection points on the network analyzes packets flowing on the network to generate traffic statistical information at regular aggregation intervals, and generates traffic fluctuation notification information when a traffic fluctuation is detected; a second step in which the data collection device constructs a database based on the traffic statistical information and traffic fluctuation notification information obtained from the plurality of collection points; The first step comprises: a third step of receiving a packet from the network; a fourth step of analyzing the packet received in the third step; a fifth step of identifying whether the received packet belongs to a flow for which data collection is to be performed based on the analysis result of the fourth step; a sixth step of acquiring traffic statistics information for each flow of packets determined to be flows for which data collection is to be performed in the fifth step; a seventh step of aggregating the traffic statistical information acquired in the sixth step for each flow and for each aggregation period; an eighth step of generating traffic fluctuation notification information when a traffic fluctuation is detected based on the traffic statistical information acquired in the sixth step; a ninth step of transmitting the traffic statistical information and the traffic fluctuation notification information aggregated for each flow to the data aggregation device.

5. 5. The traffic statistics information acquisition method according to claim 4, The eighth step of the traffic statistical information acquisition method is characterized in that it includes a step of calculating the difference between the latest traffic statistical information acquired in the sixth step and the immediately preceding traffic statistical information for each flow, and determining that a traffic fluctuation is occurring if the calculated difference exceeds a predetermined threshold.

6. 6. The traffic statistics information acquisition method according to claim 4, The second step includes: a tenth step of receiving traffic statistical information and traffic fluctuation notification information transmitted from the data collection device; and an eleventh step of classifying the traffic statistical information and traffic fluctuation notification information received in the tenth step by flow and additionally registering the classified information in the database for the corresponding flow.

Citation Information

Patent Citations

  • Control device and communication method

    JP2015188186A

  • Information processing system, information processing device, and information processing program

    JP2019047254A