Analytical device, analytical method, analytical program, and analytical system

The analysis device addresses the challenge of analyzing network traffic on a per-VPN basis by using a system that updates and matches VPN user associations with packet headers, ensuring accurate traffic analysis despite changes in VPN associations.

JP7786589B2Active Publication Date: 2025-12-16NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024536707
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-07-28
Publication Date
2025-12-16
Estimated Expiration
2042-07-28

AI Technical Summary

Technical Problem

Conventional techniques face difficulties in analyzing network traffic on a per-VPN basis when the association between a user and a VPN changes.

Method used

An analysis device that includes a memory unit to store linking information associating VPN users with outer packet headers, an acquisition unit to update this information based on network management systems, a receiver to acquire xFlow packets, and a matching unit to identify VPN users by matching packet headers with stored information.

Benefits of technology

Enables traffic analysis on a VPN-by-VPN basis, even when user VPN associations change, by updating and matching packet headers with stored information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007786589000001
    Figure 0007786589000001
  • Figure 0007786589000002
    Figure 0007786589000002
  • Figure 0007786589000003
    Figure 0007786589000003
Patent Text Reader

Abstract

This analysis device (40) stores a linking information DB in which information identifying a user of a VPN is associated with information pertaining to an Outer header of a capsulated packet. The analysis device (40) acquires information from an OpS which is a management system that manages communication apparatuses included in a network. The analysis device (40) updates the linking information DB on the basis of the acquired information from the OpS. The analysis device (40) receives an xFlow packet generated on the basis of a sampled capsulated packet, and including the information pertaining to an Outer header of a capsulated packet and statistical information of a flow including the capsulated packet. The analysis device (40) compares the linking information DB and the information pertaining to an Outer header included in the xFlow packet and identifies the user of a VPN to which the xFlow packet is transmitted.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an analysis device, an analysis method, an analysis program, and an analysis system. [Background technology]

[0002] Conventionally, xFlow is known as a technology for network monitoring and traffic trend analysis.

[0003] xFlow is a method for collecting and analyzing traffic by transferring statistical information calculated from the header information of sampled packets, or the header portion itself (header sample) (see, for example, Patent Document 1).

[0004] Also, a packet encapsulation technique is known in the art, which embeds a packet in the payload of another packet on a network and transfers the other packet.

[0005] Also, a format conversion technique is known that enables extraction and analysis of a packet inside a capsule in a header sample (hereinafter referred to as an inner packet), such as a raw packet (see, for example, Patent Document 1).

[0006] Furthermore, for example, a technique is known in which, for encapsulated packets, the header of an inner packet and the header of a packet outside the capsule (hereinafter referred to as an outer packet) are associated with each other and registered in a database (see, for example, Patent Document 2). [Prior art documents] [Patent documents]

[0007] [Patent Document 1] Japanese Patent Application Publication No. 2019-097069 [Patent Document 2] Japanese Patent Publication No. 2020-174257 Summary of the Invention [Problem to be solved by the invention]

[0008] However, the conventional techniques have a problem in that when the association between a user and a VPN (Virtual Private Network) changes, it may be difficult to analyze traffic on a per-VPN basis. [Means for solving the problem]

[0009] In order to solve the above-mentioned problems and achieve the object, the analysis device is characterized by having: a memory unit that stores linking information that associates information that identifies a VPN user with information on the outer header of an encapsulated packet; an acquisition unit that acquires information from a management system that manages communication devices installed on a network; an update unit that updates the linking information based on the information acquired by the acquisition unit; a receiver that receives xFlow packets generated based on sampled encapsulated packets, the xFlow packets containing information on the outer header of the encapsulated packet and statistical information on the flow that contains the encapsulated packet; and a matching unit that matches the linking information with information on the outer header contained in the xFlow packets received by the receiver, and identifies the user of the VPN to which the xFlow packets are forwarded. [Effects of the Invention]

[0010] According to the present invention, when the association between a user and a VPN changes, traffic can be analyzed on a VPN-by-VPN basis. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a diagram illustrating an example of the configuration of an analysis system according to the first embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of the configuration of the conversion device according to the first embodiment. [Figure 3] FIG. 3 is a diagram illustrating the configuration and processing of the analysis device according to the first embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of flow statistical information. [Figure 5] FIG. 5 is a diagram illustrating the configuration and processing of the analysis device according to the first embodiment. [Figure 6] FIG. 6 is a sequence diagram illustrating the flow of processing in the analysis system. [Figure 7] FIG. 7 is a flowchart illustrating the flow of the update process. [Figure 8] FIG. 8 is a flowchart illustrating the flow of the matching process. [Figure 9] FIG. 9 illustrates an example of a computer that executes an analysis program. DETAILED DESCRIPTION OF THE INVENTION

[0012] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0023] The present invention will be described in detail below with reference to the accompanying drawings, in which:

[0024] An analytical device, an analytical method, an analytical program, and an analytical system according to the present invention will be described in detail below with reference to the accompanying drawings;

[0013] [Configuration of the first embodiment] First, the configuration of a system according to the first embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram showing an example of the configuration of an analysis system according to the first embodiment.

[0014] 1, the analysis system 1 analyzes traffic on a network 14. The analysis system 1 includes a conversion device 30, an analysis device 40, a terminal device 50, an OpS 60, and an authentication server .

[0015] The network 14 is, for example, a core network, and includes a network device 11, a network device 12, and a network device 13.

[0016] Each network device is, for example, a router or a switch. The number and arrangement of network devices are not limited to the example of FIG.

[0017] The network 14 accommodates one or more networks. For example, the network device 13 is connected to networks of multiple users.

[0018] The terminal device 20 is located in a user's network (hereinafter referred to as a user network).

[0019] Here, the terminal device 20 uses a VPN to communicate via the network 14. At this time, the network 14 is configured with tunnels 15a and 15b, which are virtual communication paths.

[0020] In addition, in a VPN, the above-mentioned encapsulated packets are sent and received.

[0021] 1, the terminal device 20 transmits and receives encapsulated packets using tunnel 15a at time 12:00, while the terminal device 20 transmits and receives encapsulated packets using tunnel 15b at time 12:10.

[0022] In this way, even for the same user, the tunnel, i.e., the VPN used may change depending on the time. For example, if a user logs out of a VPN and the VPN session is lost, and then logs in again to the VPN, the VPN corresponding to that user may change.

[0023] The conversion device 30 acquires xFlow packets from the network 14. For example, the conversion device 30 acquires xFlow packets from the network device 12.

[0024] The network device 12 samples packets that generate traffic on the network 14. The packets to be sampled are assumed to be encapsulated packets.

[0025] The network device 12 then extracts the outer header (header of the outer packet) and inner header (header of the inner packet) of the sampled packet, and transfers the xFlow packet encapsulating the extracted headers to the conversion device 30.

[0026] Note that encapsulation here means embedding data in the payload section of the xFlow packet.

[0027] Furthermore, the network device 12 transfers to the conversion device 30 an xFlow packet encapsulating statistical information on the sampled packets.

[0028] Here, the statistical information is calculated based on the inner header or outer header, such as the number of packets for each flow (inner flow or outer flow) based on the inner header or outer header, or the amount of communication data (e.g., in Mbps).

[0029] For example, statistical information calculated based on the Outer header is encapsulated in an xFlow packet together with the Outer header.

[0030] This allows the conversion device 30 to obtain an xFlow packet that includes the outer header and inner header of the sampled packet, and an xFlow packet that includes statistical information.

[0031] The converter 30 converts the format of the acquired xFlow packets and transfers the converted xFlow packets to the analyzer 40.

[0032] Here, the conversion device 30 extracts statistical information of the outer flow from the acquired xFlow, and transfers the xFlow packet encapsulating the extracted statistical information to the analysis device 40.

[0033] In the tunnel 15a and the tunnel 15b, each network device transfers a packet based on the outer header of the packet.

[0034] Therefore, the analysis device 40 identifies information about the VPN of the flow based on the outer flow statistical information. For example, the analysis device 40 can identify the user of the VPN that is the source of the flow.

[0035] It is assumed that information for identifying a VPN (hereinafter, Outer information) is pre-registered in the analysis device 40. For example, a maintenance person uses a terminal device 50 to register a VPN user and Outer information in association with each other via an Ops (Operation System) 60. Hereinafter, information that associates a VPN user with Outer information will be referred to as association information.

[0036] As the VPN used by a user changes, the correspondence between the user and the outer information of the VPN changes. In response to this, the analysis device 40 updates the association information as needed. This allows the analysis device 40 to analyze traffic on a VPN-by-VPN basis, even when the association between the user and the VPN changes.

[0037] The analysis device 40 identifies the VPN corresponding to the flow by comparing the xFlow packet received from the conversion device 30 with the Outer information.

[0038] Furthermore, the analysis device 40 can perform various analyses of traffic (for example, collecting statistical information) in addition to identifying VPNs.

[0039] [Configuration of conversion device] 2 is a diagram showing an example of the configuration of a conversion device according to the first embodiment. As shown in FIG. 2, the conversion device 30 includes a communication unit 31, a storage unit 32, and a control unit 33.

[0040] The communication unit 31 is an interface for transmitting and receiving data to and from other devices, and is, for example, a network interface card (NIC).

[0041] The storage unit 32 is a storage device such as a hard disk drive (HDD), a solid state drive (SSD), an optical disk, etc. Note that the storage unit 32 may also be a data-rewritable semiconductor memory such as a random access memory (RAM), a flash memory, or a non-volatile static random access memory (NVSRAM).

[0042] The storage unit 32 stores data relating to the OS (Operating System) and various programs executed by the conversion device 30.

[0043] The control unit 33 controls the entire conversion device 30. The control unit 33 is, for example, an electronic circuit such as a CPU (Central Processing Unit), an MPU (Micro Processing Unit), or a GPU (Graphics Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array).

[0044] The control unit 33 also has an internal memory for storing programs that define various processing procedures and control data, and executes each process using the internal memory. The control unit 33 also functions as various processing units by running various programs.

[0045] For example, the control unit 33 functions as a separation unit 331 , a removal unit 332 , and a conversion unit 333 .

[0046] The separator 331 separates the xFlow packets acquired by the conversion device 30 into xFlow packets that include the outer header and inner header of the sampled packets, and xFlow packets that include statistical information.

[0047] The removal unit 332 removes the outer header from the xFlow packets separated by the separation unit 331 that contain the outer header and inner header of the sampled packet.

[0048] This allows the analysis device 40 to perform analysis using not only the outer header but also the inner header, although the analysis target in the first embodiment is the outer header.

[0049] The converter 333 generates, from the xFlow packets acquired by the converter 30, xFlow packets in a format that corresponds to the processing content of the output destination of the converter 30 (for example, the analyzer 40).

[0050] The converter 333 converts the format of xFlow packets containing statistical information from among the xFlow packets separated by the separator 331. The converter 333 may output xFlow packets containing statistical information as is.

[0051] The conversion unit 333 may also calculate statistical information from the outer header and generate an xFlow packet including the calculated statistical information.

[0052] [Analytical equipment configuration] 3 is a diagram illustrating the configuration and processing of the analysis device according to the first embodiment. As shown in FIG.

[0053] The communication unit 41 is an interface for transmitting and receiving data to and from other devices, and is, for example, a NIC.

[0054] The storage unit 42 is a storage device such as an HDD, an SSD, an optical disk, etc. The storage unit 42 may also be a data-rewritable semiconductor memory such as a RAM, a flash memory, or an NVSRAM.

[0055] The storage unit 42 stores data related to the OS and various programs executed by the analysis device 40.

[0056] For example, the storage unit 42 stores a linking information DB 421 and a statistics DB 422.

[0057] The link information DB 421 stores link information in which information related to VPNs is associated with outer information.

[0058] The user ID in the linked information DB 421 is an example of information related to VPN. The linked information DB 421 also includes N pieces of outer information (outer information_1, ..., outer information_N).

[0059] 3, the association information DB 421 includes four pieces of outer information: Src IP (source IP address), Dst IP (destination IP address), tunnel ID, and session ID. These pieces of outer information correspond to keys of the association information DB 421.

[0060] The Outer information may also be a 5-tuple. In this case, for example, Outer information_1, Outer information_2, Outer information_3, Outer information_4, and Outer information_5 correspond to the source IP address, source port number, destination IP address, destination port number, and protocol, respectively.

[0061] 3, a user ID "A" is associated with a Src IP "aaaa", a Dst IP "xxxx", a tunnel ID "10", and a session ID "100". The association information DB 421 also includes update results and update times.

[0062] Furthermore, the session ID in the first line of the association information DB 421 is "100," while the session ID in the second line is "200." This indicates that the VPN used by the user with the user ID "A" has changed.

[0063] For VPNs for which the correspondence between VPN users and outer information is known, the linking information DB 421 is registered in advance by, for example, an administrator.

[0064] On the other hand, for VPNs where the correspondence between the VPN user and the Outer information is unknown, the VPN information is automatically registered by the analysis device 40. In this case, for example, a value indicating the user ID is set to "unknown" or "Unknown."

[0065] In either case, after registration, the linked information DB 421 is updated by the analysis device 40. The process of updating the linked information DB 421 will be described later.

[0066] 4 is a diagram showing an example of flow statistics information. The statistics DB 422 contains statistical information extracted from xFlow packets.

[0067] The statistics DB 422 includes outer information corresponding to the outer information of the link information DB 421 .

[0068] 4 shows that the reception time of a flow with a flow ID of "F011" is "2022 / 7 / 10 / 11:30:00", the Src IP is "aaaa", the Dst IP is "xxxx", the tunnel ID is "10", the session ID is "100", the user ID is "A", and the Mbps is "100". In this way, in the statistics DB 422, as in the association information DB 421, the user ID and the outer information are associated with each other.

[0069] Note that Mbps is the amount of communication data and is an example of Outer statistical information.

[0070] The control unit 43 controls the entire analysis device 40. The control unit 43 is, for example, an electronic circuit such as a CPU, an MPU, or a GPU, or an integrated circuit such as an ASIC or an FPGA.

[0071] The control unit 43 also has an internal memory for storing programs that define various processing procedures and control data, and executes each process using the internal memory. The control unit 43 also functions as various processing units by running various programs.

[0072] For example, the control unit 43 functions as an acquisition unit 431, an update unit 432, a matching unit 433, a reception unit 434, and a display control unit 435.

[0073] The acquisition unit 431 acquires information for updating the association information DB 421. The acquisition unit 431 acquires information from a management system that manages communication devices provided on a network, that is, from the OpS 60.

[0074] When the acquisition unit 431 acquires the user ID and outer information from the OpS 60 , it instructs the update unit 432 to update the linked information DB 421 .

[0075] The update unit 432 updates the linked information DB 421 based on the information acquired by the acquisition unit 431. The update unit 432 returns the result of the process of updating the linked information DB 421 (OK or NG) to the acquisition unit 431.

[0076] If the update process fails as a result of executing the process to update the linked information DB 421 (update result: NG), the update unit 432 executes (retries) the process to update the linked information DB 421 again.

[0077] If the process of updating the linked information DB 421 is successful, the update unit 432 stores "OK" in the "update result" of the linked information DB 421.

[0078] The receiving unit 434 receives an xFlow packet that is generated based on a sampled encapsulated packet and that contains information about the outer header of the encapsulated packet and statistical information about the flow that contains the encapsulated packet.

[0079] The matching unit 433 matches the association information DB 421 with information about the outer header included in the xFlow packet received by the receiving unit 434, and identifies the user of the VPN to which the xFlow packet is forwarded.

[0080] The matching unit 433 extracts the outer header (for example, Src IP, Destination IP, tunnel ID, and session ID) from the xFlow packet received by the receiving unit 434, which contains the outer header and statistical information related to the outer header.

[0081] Then, the matching unit 433 compares the extracted outer header with the outer information in the link information DB 421 .

[0082] When the Outer header matches the Outer information in the linking information DB 421, the matching unit 433 stores the Outer header together with the statistical information in the statistical DB 422. The Outer header is stored in the statistical DB 422 as Outer information.

[0083] If the information about the Outer header associated with the information identifying the VPN user does not match the information about the Outer header included in the xFlow packet received by the receiving unit 434, the matching unit 433 associates the information about the Outer header included in the xFlow packet with a value meaning that it is unknown and stores it in the memory unit 42.

[0084] For example, if the Outer header does not match the Outer information in the linked information DB 421 (if there is no match), the matching unit 433 adds the user ID "unknown" to the Outer header and adds it to the linked information DB 421.

[0085] If the matching unit 433 finds that the information on the Outer header associated with the information identifying the VPN user matches the information on the Outer header included in the xFlow packet received by the receiving unit 434, the display control unit 435 displays the statistical information included in the xFlow packet on the screen of the terminal device 50. In this case, the display control unit 435 provides the statistical information obtained from the statistical DB 422 to the terminal device 50 as a GUI.

[0086] Because the association information DB 421 is updated as needed, the analysis device 10 can visualize the statistical information for each period, even if the user's VPN changes. For example, as shown in Fig. 1, the analysis device 10 can visualize (display on screen) the statistical information for the period before 12:10 and the period after 12:10.

[0087] The association information DB 421 includes an update time that indicates the time when the association information DB 421 was updated. Therefore, if the matching unit 433 finds a match between the association information DB 421 and the information about the Outer header included in the xFlow packet received by the receiving unit 434, the display control unit 435 can display the statistical information included in the xFlow packet together with the update time on the screen of the terminal device.

[0088] The terminal device 50 is a terminal device used by a maintenance person, and is, for example, a personal computer, a smartphone, or the like.

[0089] (How to update binding information using authentication server logs) 5, the analysis device 40 can update the linking information DB 421 using information obtained from the authentication server 70. Fig. 5 is a diagram illustrating the configuration and processing of the analysis device according to the first embodiment.

[0090] 5, the authentication server 70 authenticates users for VPN and stores the authentication results as a log, which contains at least the user ID and the time when the authentication was performed.

[0091] The acquisition unit 431 acquires the time when authentication was performed for the user's VPN from the VPN authentication server 70. The acquisition unit 431 can acquire the log from the authentication server 70 by polling (for example, SNMP polling). The authentication server 70 provides the log to the acquisition unit 431 as a polling response.

[0092] The acquisition unit 431 may also acquire the log from the authentication server 70 by a trap (for example, an SNMP trap).

[0093] If the time obtained from the authentication server 70 is after the time when the linking information DB421 for the user was last updated, the update unit 432 obtains information about the user from the OpS60 and updates the linking information DB421 based on the obtained information.

[0094] That is, the update unit 432 requests the difference from the acquisition unit 431. The acquisition unit 431 requests the difference from the OpS 60 and receives the difference. Then, the update unit 432 acquires the difference via the acquisition unit 431.

[0095] The difference is information about the user that has occurred since the link information DB 421 was last updated.

[0096] 5, the log states that user A (user ID "A") was authenticated at 11:30 and 12:09. Also, assume that only the first row (updated time: 11:30:00) exists in the association information DB 421 at the time the log is acquired.

[0097] The time 12:09 written in the log is after 11:30, the time when the linked information DB 421 for user A was last updated, so the update unit 432 requests the difference.

[0098] This reduces the frequency with which information is obtained from the OpS 60.

[0099] [Processing flow] The processing flow of the analysis system 1 will be described with reference to Fig. 6. Fig. 6 is a sequence diagram illustrating the processing flow of the analysis system.

[0100] First, the OpS 60 stores the linking information in the acquisition unit 431 (step S101). The acquisition unit 431 commands the update unit 432 to update the linking information DB 421 (step S102).

[0101] The update unit 432 updates the association information DB 421 (step S103) and notifies the acquisition unit 431 of the update result (step S104).

[0102] If the update result is NG, the acquisition unit 431 causes the update unit 432 to retry the update (step S105).

[0103] After the association information DB 421 is updated (step S106), the receiving unit 434 receives the outer flow statistical information and passes it to the matching unit 433 (step S107).

[0104] The matching unit 433 matches the linking information DB 421 with the outer flow statistical information (step S108). The matching unit 433 adds the linking information based on the matching result and stores the outer flow statistical information in the statistical DB 422 (step S109).

[0105] Thereafter, the analysis device 40 visualizes the outer flow statistical information stored in the statistical DB 422 on a per-user basis and provides the visualized information to the terminal device 20 (step S110).

[0106] The flow of the update process performed by the analysis device 40 will be described with reference to Fig. 7. Fig. 7 is a flowchart illustrating the flow of the update process.

[0107] 7, first, the analysis device 40 collects the linking information from the OpS 60 (step S201). The analysis device 40 may collect the linking information from the OpS 60 periodically, or may collect the linking information when it is determined that there is a possibility of a difference based on the log of the authentication server 70.

[0108] Next, the analysis device 40 attempts to update the linking information based on the collected information (step S202). If the update is successful (step S203, Yes), the analysis device 40 ends the process. If the update is not successful (step S203, No), the analysis device 40 returns to step S202 and repeats the process (retry).

[0109] The flow of the matching process by the analysis device 40 will be described with reference to Fig. 8. Fig. 8 is a flowchart illustrating the flow of the matching process.

[0110] 8, first, the analysis device 40 receives the outer flow statistical information (step S301). The outer flow statistical information is included in the xFlow packets output from the conversion device 30.

[0111] The analysis device 40 checks the received Outer flow statistical information against the linking information (step S302). At this time, the analysis device 40 compares the Outer information in the linking information DB 421 with the Outer header corresponding to the Outer statistical information.

[0112] If the Outer header and the Outer information completely match (Yes at step S303), the analysis device 40 stores the received Outer flow statistical information in the DB (statistics DB 422) (step S304).

[0113] On the other hand, if the Outer header and the Outer information do not completely match (No at step S303), the analysis device 40 adds an unknown VPN identifier to the association information DB 421 (step S305).

[0114] [Effects of the first embodiment] The storage unit 42 stores an association information DB 421 that associates information identifying VPN users with information about the outer header of encapsulated packets. The acquisition unit 431 acquires information from a management system that manages communication devices installed on the network. The update unit 432 updates the association information DB 421 based on the information acquired by the acquisition unit 431. The reception unit 434 receives xFlow packets that are generated based on sampled encapsulated packets and that contain information about the outer header of the encapsulated packet and statistical information about the flow that includes the encapsulated packet. The matching unit 433 matches the association information DB 421 with the information about the outer header included in the xFlow packet received by the reception unit 434, and identifies the user of the VPN to which the xFlow packet is forwarded.

[0115] This allows traffic to be analyzed on a VPN-by-VPN basis when the association between a user and a VPN changes.

[0116] If the update process fails as a result of executing the process to update the linked information DB 421, the update unit 432 re-executes the process to update the linked information DB 421. This ensures that the linked information DB 421 is updated reliably.

[0117] The association information DB 421 includes an update time indicating the time when the association information DB 421 was updated. If the matching unit 433 finds a match between the association information DB 421 and the information about the Outer header included in the xFlow packet received by the receiving unit 434, the display control unit displays the statistical information included in the xFlow packet together with the update time on the screen of the terminal device. This makes it possible to show when the VPN used by the user changed, along with the statistical information.

[0118] The acquisition unit 431 acquires the time when authentication was performed for the user's VPN from the VPN authentication server 70. If the time is after the time when the linked information DB 421 for the user was last updated, the update unit 432 acquires information about the user from the management system and updates the linked information DB 421 based on the acquired information. In this way, the frequency of acquiring information from the OpS 60 can be minimized based on the log obtained from the authentication server 70.

[0119] [System configuration, etc.] Furthermore, the components of each device shown in the figure are functional concepts and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown, and all or part of the devices can be functionally or physically distributed or integrated in any unit depending on various loads, usage conditions, etc. Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU (Central Processing Unit) and a program analyzed and executed by the CPU, or can be realized as hardware using wired logic. Note that the program may be executed not only by the CPU but also by other processors such as a GPU.

[0120] Furthermore, among the processes described in this embodiment, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method.In addition, the information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified.

[0121] [program] In one embodiment, the analysis device 40 can be implemented by installing an analysis program that executes the above-described analysis process as package software or online software on a desired computer. For example, by having an information processing device execute the above-described analysis program, the information processing device can function as the analysis device 40. The information processing device referred to here includes desktop and notebook personal computers. Other information processing devices also include mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handyphone Systems), as well as slate terminals such as PDAs (Personal Digital Assistants).

[0122] The analysis device 40 can also be implemented as an analysis server device that provides services related to the above-mentioned analysis processing to clients, with terminal devices used by users as clients. For example, the analysis server device is implemented as a server device that receives xFlow packets as input and outputs analysis results as output. In this case, the analysis server device may be implemented as a web server or as a cloud that provides services related to the above-mentioned analysis processing through outsourcing.

[0123] 9 is a diagram showing an example of a computer that executes an analysis program. The computer 1000 includes, for example, a memory 1010 and a CPU 1020. The computer 1000 also includes a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0124] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM (Random Access Memory) 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to a mouse 1110 and a keyboard 1120, for example. The video adapter 1060 is connected to a display 1130, for example.

[0125] The hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, the programs that define each process of the analysis device 40 are implemented as program modules 1093 in which computer-executable code is written. The program modules 1093 are stored, for example, in the hard disk drive 1090. For example, a program module 1093 for executing processes similar to those of the functional configuration of the analysis device 40 is stored in the hard disk drive 1090. The hard disk drive 1090 may be replaced by an SSD (Solid State Drive).

[0126] Furthermore, setting data used in the processing of the above-described embodiment is stored as program data 1094, for example, in the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads the program module 1093 or the program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as necessary, and executes the processing of the above-described embodiment.

[0127] The program module 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090, but may also be stored in, for example, a removable storage medium and read by the CPU 1020 via the disk drive 1100 or the like. Alternatively, the program module 1093 and program data 1094 may be stored in another computer connected via a network (such as a local area network (LAN) or a wide area network (WAN)). The program module 1093 and program data 1094 may then be read by the CPU 1020 from the other computer via the network interface 1070. [Explanation of symbols]

[0128] 14 Network 15a and 15b Tunnels 11, 12, 13 Network equipment 20, 50 terminal equipment 30 Conversion Device 40 Analyzer 60 Ops 70 Authentication Server 31, 41 Communications Department 32, 42 Storage section 33, 43 Control section 331 Separation section 332 Removal section 333 Conversion Unit 421 Linked Information DB 422 Statistics DB 431 Acquisition Department 432 Update Department 433 Butt joint 434 Receiving Unit 435 Display control unit

Claims

1. a storage unit that stores association information that associates information for identifying a VPN user with information about the outer header of an encapsulated packet; an acquisition unit that acquires information from a management system that manages communication devices provided on a network; an update unit that updates the linking information based on the information acquired by the acquisition unit, and if the update process fails as a result of the execution of the process of updating the linking information, executes the process of updating the linking information again; a receiver that receives an xFlow packet generated based on sampled encapsulated packets, the xFlow packet including information about the outer header of the encapsulated packet and statistical information about a flow including the encapsulated packet; a matching unit that matches the linking information with information about an outer header included in an xFlow packet received by the receiving unit, and identifies a user of a VPN to which the xFlow packet is forwarded; An analytical device comprising:

2. a storage unit that stores association information that associates information for identifying a VPN user with information on the outer header of an encapsulated packet, the association information including an update time that indicates the time when the association information was updated; an acquisition unit that acquires information from a management system that manages communication devices provided on a network; an update unit that updates the linking information based on the information acquired by the acquisition unit; a receiver that receives an xFlow packet generated based on sampled encapsulated packets, the xFlow packet including information about the outer header of the encapsulated packet and statistical information about a flow including the encapsulated packet; a matching unit that matches the linking information with information about an outer header included in an xFlow packet received by the receiving unit, and identifies a user of a VPN to which the xFlow packet is forwarded; a display control unit that, when the matching unit finds that the linking information matches information about an Outer header included in the xFlow packet received by the receiving unit, displays the statistical information included in the xFlow packet together with the update time on a screen of a terminal device; An analytical device comprising:

3. a storage unit that stores association information that associates information for identifying a VPN user with information about the outer header of an encapsulated packet; an acquisition unit that acquires information from a management system that manages communication devices provided on the network, and acquires the time when authentication for the user's VPN was performed from an authentication server of the VPN; an update unit that acquires information about the user from the management system and updates the associated information based on the acquired information if the time is after the time when the associated information about the user was last updated; a receiver that receives an xFlow packet generated based on sampled encapsulated packets, the xFlow packet including information about the outer header of the encapsulated packet and statistical information about a flow including the encapsulated packet; a matching unit that matches the linking information with information about an outer header included in an xFlow packet received by the receiving unit, and identifies a user of a VPN to which the xFlow packet is forwarded; An analytical device comprising:

4. An analysis method executed by an analysis device having a storage unit that stores association information that associates information for identifying a VPN user with information on an outer header of an encapsulated packet, the method comprising: an acquisition step of acquiring information from a management system that manages communication devices provided on the network; an updating step of updating the linking information based on the information acquired by the acquiring step, and if the updating step fails as a result of executing the updating step, executing the processing to update the linking information again; a receiving step of receiving an xFlow packet generated based on the sampled encapsulated packets, the xFlow packet including information on the outer header of the encapsulated packets and statistical information on the flow including the encapsulated packets; a matching step of matching the linking information with information about an outer header included in the xFlow packet received in the receiving step, and identifying a user of a VPN to which the xFlow packet is forwarded; An analytical method comprising:

5. 1. An analysis method executed by an analysis device having a storage unit that stores association information that associates information for identifying a VPN user with information on an outer header of an encapsulated packet, the association information including an update time that indicates a time when the association information was updated, the method comprising: an acquisition step of acquiring information from a management system that manages communication devices provided on the network; an updating step of updating the linking information based on the information acquired in the acquiring step; a receiving step of receiving an xFlow packet generated based on the sampled encapsulated packets, the xFlow packet including information on the outer header of the encapsulated packets and statistical information on the flow including the encapsulated packets; a matching step of matching the linking information with information about an outer header included in the xFlow packet received in the receiving step, and identifying a user of a VPN to which the xFlow packet is forwarded; a display control step of displaying the statistical information included in the xFlow packet together with the update time on a screen of a terminal device when the matching step results in a match between the linking information and information about an Outer header included in the xFlow packet received in the receiving step; An analytical method comprising:

6. An analysis method executed by an analysis device having a storage unit that stores association information that associates information for identifying a VPN user with information on an outer header of an encapsulated packet, the method comprising: an acquisition step of acquiring information from a management system that manages communication devices provided on the network, and acquiring the time when authentication for the user's VPN was performed from an authentication server of the VPN; an updating step of acquiring information about the user from the management system and updating the linked information based on the acquired information if the time is after the time when the linked information about the user was last updated; a receiving step of receiving an xFlow packet generated based on the sampled encapsulated packets, the xFlow packet including information on the outer header of the encapsulated packets and statistical information on the flow including the encapsulated packets; a matching step of matching the linking information with information about an outer header included in the xFlow packet received in the receiving step, and identifying a user of a VPN to which the xFlow packet is forwarded; An analytical method comprising:

7. An analysis device having a storage unit that stores association information that associates information for identifying a VPN user with information about the outer header of an encapsulated packet, an acquisition step of acquiring information from a management system that manages communication devices provided on a network; an updating step of updating the linking information based on the information acquired by the acquiring step, and if the updating process fails as a result of the execution of the process of updating the linking information, executing the process of updating the linking information again; a receiving step of receiving an xFlow packet generated based on the sampled encapsulated packets, the xFlow packet including information on the outer header of the encapsulated packets and statistical information on the flow including the encapsulated packets; a matching step of matching the linking information with information about an outer header included in the xFlow packet received in the receiving step, and identifying a user of a VPN to which the xFlow packet is forwarded; An analysis program characterized by executing the above.

8. An analysis device having a storage unit that stores association information that associates information for identifying a VPN user with information on the outer header of an encapsulated packet, the association information including an update time that indicates the time when the association information was updated, an acquisition step of acquiring information from a management system that manages communication devices provided on a network; an updating step of updating the linking information based on the information acquired by the acquiring step; a receiving step of receiving an xFlow packet generated based on the sampled encapsulated packets, the xFlow packet including information on the outer header of the encapsulated packets and statistical information on the flow including the encapsulated packets; a matching step of matching the linking information with information about an outer header included in the xFlow packet received in the receiving step, and identifying a user of a VPN to which the xFlow packet is forwarded; a display control step of displaying the statistical information included in the xFlow packet together with the update time on a screen of a terminal device when the matching step results in a match between the linking information and information about an Outer header included in the xFlow packet received in the receiving step; An analysis program characterized by executing the above.

9. An analysis device having a storage unit that stores association information that associates information for identifying a VPN user with information about the outer header of an encapsulated packet, an acquisition step of acquiring information from a management system that manages communication devices provided on the network, and acquiring the time when authentication for the user's VPN was performed from an authentication server of the VPN; an updating step of acquiring information about the user from the management system and updating the associated information based on the acquired information if the time is after the time when the associated information about the user was last updated; a receiving step of receiving an xFlow packet generated based on the sampled encapsulated packets, the xFlow packet including information on the outer header of the encapsulated packets and statistical information on the flow including the encapsulated packets; a matching step of matching the linking information with information about an outer header included in the xFlow packet received in the receiving step, and identifying a user of a VPN to which the xFlow packet is forwarded; An analysis program characterized by executing the above.

10. An analysis system having an OpS, which is a management system that manages communication devices provided on a network, and an analysis device, The analysis device a storage unit that stores association information that associates information for identifying a VPN user with information about the outer header of an encapsulated packet; an acquisition unit that acquires information from the OpS; an update unit that updates the linking information based on the information acquired by the acquisition unit, and if the update process fails as a result of the execution of the process of updating the linking information, executes the process of updating the linking information again; a receiver that receives an xFlow packet generated based on sampled encapsulated packets, the xFlow packet including information about the outer header of the encapsulated packet and statistical information about a flow including the encapsulated packet; a matching unit that matches the linking information with information about an outer header included in an xFlow packet received by the receiving unit, and identifies a user of a VPN to which the xFlow packet is forwarded; An analysis system comprising:

11. An analysis system having an OpS, which is a management system that manages communication devices provided on a network, and an analysis device, The analysis device a storage unit that stores association information that associates information for identifying a VPN user with information on the outer header of an encapsulated packet, the association information including an update time that indicates the time when the association information was updated; an acquisition unit that acquires information from the OpS; an update unit that updates the linking information based on the information acquired by the acquisition unit; a receiver that receives an xFlow packet generated based on sampled encapsulated packets, the xFlow packet including information about the outer header of the encapsulated packet and statistical information about a flow including the encapsulated packet; a matching unit that matches the linking information with information about an outer header included in an xFlow packet received by the receiving unit, and identifies a user of a VPN to which the xFlow packet is forwarded; a display control unit that, when the matching unit finds that the linking information matches information about an Outer header included in the xFlow packet received by the receiving unit, displays the statistical information included in the xFlow packet together with the update time on a screen of a terminal device; An analysis system comprising:

12. An analysis system having an OpS, which is a management system that manages communication devices provided on a network, and an analysis device, The analysis device a storage unit that stores association information that associates information for identifying a VPN user with information about the outer header of an encapsulated packet; an acquisition unit that acquires information from the OpS and acquires the time when authentication for the user's VPN was performed from an authentication server of the VPN; an update unit that acquires information about the user from the management system and updates the associated information based on the acquired information if the time is after the time when the associated information about the user was last updated; a receiver that receives an xFlow packet generated based on sampled encapsulated packets, the xFlow packet including information about the outer header of the encapsulated packet and statistical information about a flow including the encapsulated packet; a matching unit that matches the linking information with information about an outer header included in an xFlow packet received by the receiving unit, and identifies a user of a VPN to which the xFlow packet is forwarded; An analysis system comprising:

Citation Information

Patent Citations

  • Format converter and format conversion program

    JP2019097069A

  • Registration system, registration method, and registration program

    JP2020174257A

  • Format conversion device, method, and program

    JP2021090161A