Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

11 results about "Port mirroring" patented technology

Port mirroring is used on a network switch to send a copy of network packets seen on one switch port (or an entire VLAN) to a network monitoring connection on another switch port. This is commonly used for network appliances that require monitoring of network traffic such as an intrusion detection system, passive probe or real user monitoring (RUM) technology that is used to support application performance management (APM). Port mirroring on a Cisco Systems switch is generally referred to as Switched Port Analyzer (SPAN) or Remote Switched Port Analyzer (RSPAN). Other vendors have different names for it, such as Roving Analysis Port (RAP) on 3Com switches.

Data processing method of block chain network and related products thereof

The invention discloses a data processing method of a block chain network and a related product thereof, the block chain network comprises a plurality of block chain nodes, the plurality of block chain nodes comprise block outlet nodes, the plurality of block chain nodes carry out data interaction based on a switch, the switch has a port mirror image module, and the port mirror image module is connected with the block outlet nodes. The method comprises the following steps: receiving a first data packet sent by a switch through a port mirroring module, wherein the first data packet is obtained by mirroring an obtained network data packet related to an out-block node through the port mirroring module by the switch; performing data analysis processing on the first data packet to obtain analysis data; and detecting the out-of-block node based on the analysis data to obtain a detection result which indicates the out-of-block process of the out-of-block node. By adopting the method and the device, the accuracy of detecting and processing the out-of-block node can be improved.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

DDoS attack detection method, apparatus, and system

The application provides a DDoS attack detection method, device and system, the method comprising: capturing network card traffic data through Scapy, the network card traffic data being traffic sent to a target machine obtained from a switch through port mirroring technology; based on a pre-trained classifier, determining whether a DDoS attack will occur according to the network card traffic data, if yes, determining a malicious MAC address according to the network card traffic data based on a statistical method of a CRH algorithm, and controlling the switch to perform a filtering operation on the traffic sent to the target machine according to the malicious MAC address. The method not only has high processing efficiency, but also can accurately distinguish malicious traffic in mixed traffic, correctly detect the MAC address of a host initiating a DDoS attack, and has high detection precision.
Owner:XIDIAN UNIV

Video and audio signal monitoring method of switch node port mirror image

PendingCN121907668ATransmissionTelecommunicationsPort mirroring
The invention relates to the technical field of video and audio signal monitoring, in particular to a switch node port mirroring video and audio signal monitoring method, which comprises the following steps of: creating a dynamic mirroring point: creating a mirroring point at each node in a target node group based on a network topology structure, a traffic limit and a fault removal score of a candidate node; multi-dimensional data association collection: collecting mirror image flow data through the created mirror image point, collecting network equipment performance index data at the same time, and adding a synchronization timestamp mark to all the collected data; fault propagation path modeling: constructing a real-time fault propagation path model based on the network topology data and the collected fault data; and fault source automatic positioning: analyzing the fault propagation path model, and determining the initial occurrence position and time of the fault. The device can dynamically construct the mirror image, accurately determine the fault, adaptively control the flow and visualize, and efficiently improve the operation and maintenance of the video and audio network.
Owner:ZHONGYI INSTECH TECH CO LTD +1

Scheduling adaptation method for industrial PON (Passive Optical Network) and industrial Ethernet

The invention discloses a scheduling adaptation method for an industrial PON and an industrial Ethernet, and the method comprises the steps: constructing a protocol-optical resource mapping semantic model, abstracting the communication demands of different industrial Ethernet protocols into a unified data structure containing a time-sensitive service level, a flow feature and a communication period parameter, mapping to generate corresponding scheduling demand parameters required by the industrial PON management platform; target traffic is sensed in real time based on a port mirroring technology, protocol identification is carried out by using a protocol-optical resource mapping semantic model, the bandwidth demand and transmission time sequence characteristics of industrial Ethernet service flow are further analyzed, the analyzed bandwidth demand and transmission time sequence characteristics are mapped into scheduling demand parameters of an industrial PON, and the scheduling demand parameters of the industrial PON are mapped to the target traffic. And the industrial PON management platform generates and issues a deterministic scheduling instruction based on the received scheduling demand parameters, so that deterministic transmission service is realized. According to the invention, low-delay, low-jitter and high-reliability transmission service can be provided for the multi-protocol industrial equipment.
Owner:INST OF IND INTERNET CHONGQING UNIV OF POSTS & TELECOMM

Remote switch port mirroring in network

PendingCN121771147AData switching networksPort mirroringInternet traffic
The invention relates to remote switch port mirroring in a network. An example network switch includes: a hardware platform; a first switch port supported by the hardware platform and configured to receive a first network traffic of a network; and switch logic supported by the hardware platform, configured to replicate the first network traffic received by the first switch port to generate mirrored traffic for a second switch port in the network, the switch logic further configured to embed metadata in the mirrored traffic, the metadata includes information external to the first network traffic, and the switch logic is further configured to send the mirrored traffic to a device connected to the second switch port.
Owner:AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD

Local area network exit abnormal flow detection method and device

PendingCN121509082ASecuring communicationPort mirroringEngineering
The invention belongs to the technical field of network abnormal traffic detection, and particularly provides a local area network exit abnormal traffic detection method and device, which utilizes the port mirroring function of the existing core network switching equipment to losslessly copy exit traffic to an independent mirroring port in a bypass mode, thereby improving the detection efficiency. And real-time deep analysis is carried out on the mirror image traffic by means of general computing equipment provided with traffic analysis software, abnormal traffic is accurately identified based on a threat feature rule base, and an infected terminal in a local area network is rapidly positioned according to source address information of the abnormal traffic. By means of the arrangement, monitoring of the outlet flow of the local area network is achieved, the cost is low, the blind area problem caused by the fact that professional safety equipment cannot be deployed in scenes such as county-level branches due to cost limitation is solved, and the high-standard requirement of industries such as insurance for network safety can be met.
Owner:CHINA LIFE INSURANCE CO LTD HEBEI BRANCH

Method and system for online testing of dcs network load and dual network switching performance

PendingCN122293550AAd hoc testingOnline test
This application relates to an online testing method for DCS network load and dual-network switching performance. The method includes: responding to a unit shutdown and a signal where field I / O signals are securely isolated, generating and activating a batch of temporary test points in at least one pair of controllers in the DCS for network-wide broadcasting to simulate peak network load; when the peak network load exceeds a preset load threshold, forcibly triggering a primary / backup switching operation between the DCS's A and B networks; collecting traffic data from the A and B networks via switch port mirroring; recording application layer service data within the DCS; and analyzing network switching performance indicators based on the traffic and service data. This application solves the problem of inaccurately measuring the operating status of thermal power generating units, and the network-wide broadcasting of batch temporary test points can reproduce the communication characteristics of the DCS under full load or even overload conditions.
Owner:HUADIAN ELECTRIC POWER SCI INST CO LTD

Virtual machine agentless IP self-recovery method suitable for hyper-converged architecture

ActiveCN121357155BTransmissionPort mirroringRollback Operation
The present application relates to a virtual machine agentless IP self-recovery method suitable for super-converged architecture, divides self-recovery IP pool and constructs MAC-VM asset library based on etcd distributed cluster; through OpenvSwitch port mirror listening ARP flow, combines multiple confirmation mechanism to accurately identify IP conflict; according to conflict MAC address, locates conflict virtual machine and corresponding CephRBD disk path; comprehensively judges virtual machine IP configuration mode according to multiple source data; according to running state priority, configuration mode second, response time bottom-up priority, determines repair target; according to DHCP mode, static agentless mode, static agent mode, executes hierarchical repair strategy; through repair verification and closed loop mechanism, ensures repair effect, and executes rollback operation when failing.The present application is compatible with agentless environment and DHCP and static IP mixed deployment scene, realizes permanent repair of IP conflict, greatly reduces manual intervention, improves stability and autonomy of super-converged platform, and has advantages of data safety and reliability, production level operation compatibility and the like.
Owner:SICHUAN HUACUNZHIGU TECH CO LTD

Implementation and test method of configurable multi-port two-layer Ethernet switch simulation model

PendingCN121792419ATransmissionVirtual LANPort mirroring
The technical scheme of the invention discloses a method for realizing and testing a simulation model of a configurable multi-port two-layer Ethernet switch. The invention discloses an implementation method for constructing a high-fidelity virtual Ethernet switch model on a universal host and a method for testing the implemented model. The virtual switch model realized by the invention can simulate the working characteristics of a real two-layer Ethernet switch in a universal host environment, and covers functional modules of interface management, virtual local area network (VLAN), two-layer forwarding, multicast, spanning tree, link aggregation, port mirroring and the like.
Owner:EAST CHINA INST OF COMPUTING TECH

IPSEC message mirroring method and device

PendingCN121664822ASecuring communicationPort mirroringIPsec
The invention discloses an IPSEC (Internet Protocol Security) message mirroring method and IPSEC message mirroring equipment. The method comprises the following steps: step 1, configuring a new command; 2, the IPSEC encryption module judges whether the command in the step 1 is configured or not before encryption, and if the command is not configured, original process encryption is carried out and is kept unchanged; step 3, if the command in the step 1 is configured; after IPSEC encryption, copying an original message to a cache, and continuing to encrypt the original message; if the encryption process fails or is abnormally discarded, the message is discarded; the cache is emptied, and the copied message is also discarded; step 4, if the encryption is normal, performing port mirroring processing on the cached message before encryption at the last step of sending the IPSEC encrypted message at the interface, and sending the message to a target mirroring port; and after mirroring, the cache is emptied for cyclic caching of the next IPSEC original message. According to the invention, an accurate positioning method can be provided when the SDWAN service has a fault, and the fault can be positioned in time.
Owner:SHENZHEN WANTONG POST & TELECOMM TECH CO LTD

Remote switch port mirroring in a network

PendingUS20260095420A1Data switching networksPort mirroringNetwork switch
An example network switch includes: a hardware platform; a first switch port, supported by the hardware platform, configured to receive first network traffic for a network; and switch logic, supported by the hardware platform, configured to copy the first network traffic received by the first switch port to generate mirrored traffic for a second switch port in the network, the switch logic further configured to embed metadata into the mirrored traffic, the metadata including information extrinsic to the first network traffic, the switch logic further configured to send the mirrored traffic to a device connected to the second switch port.
Owner:AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD