[go: up one dir, main page]

TWI389504B - IP network traffic error detection and analysis system - Google Patents

IP network traffic error detection and analysis system Download PDF

Info

Publication number
TWI389504B
TWI389504B TW98125298A TW98125298A TWI389504B TW I389504 B TWI389504 B TW I389504B TW 98125298 A TW98125298 A TW 98125298A TW 98125298 A TW98125298 A TW 98125298A TW I389504 B TWI389504 B TW I389504B
Authority
TW
Taiwan
Prior art keywords
network
traffic
analysis
error detection
module
Prior art date
Application number
TW98125298A
Other languages
Chinese (zh)
Other versions
TW201105065A (en
Original Assignee
Chunghwa Telecom Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Chunghwa Telecom Co Ltd filed Critical Chunghwa Telecom Co Ltd
Priority to TW98125298A priority Critical patent/TWI389504B/en
Publication of TW201105065A publication Critical patent/TW201105065A/en
Application granted granted Critical
Publication of TWI389504B publication Critical patent/TWI389504B/en

Links

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Description

IP網路訊務查錯與分析系統IP network traffic troubleshooting and analysis system

本發明係關於一種IP網路訊務查錯與分析系統,特別為一種運用Cloud Computing架構達成集中控管與分析各IP骨幹網路的訊務之功能。The invention relates to an IP network traffic error detection and analysis system, in particular to a function of centrally controlling and analyzing the traffic of each IP backbone network by using the Cloud Computing architecture.

目前傳統的網路的訊務查錯與分析,主要使用Client-Server模式,需要各種不同廠牌的Client設備與搭配之Server。其缺點是若需要5種以上訊務查錯與分析功能,每個模組再有配合5種以上軟體執行,即需要25種以上Client訊務送至25個以上Server上,現階段若不整合,則屬不可行之模式。At present, the traditional network traffic error detection and analysis mainly uses the Client-Server mode, which requires a client device of various brands and a matching server. The disadvantage is that if more than 5 types of traffic troubleshooting and analysis functions are required, each module can be executed with more than 5 types of software, that is, more than 25 types of client services are required to be sent to more than 25 servers. , is a mode that is not feasible.

本案發明人鑑於上述習用技術所衍生之各項缺點,乃亟思加以改良創新,並經多年苦心孤詣潛心研究後,終於成功研發完成本案IP網路訊務查錯與分析系統。係利用Cloud Computing的「分散式運算」(distributed computing)概念,將龐大運算作業拆成千百個較小作業,在遠端、多部伺服器上同時動作。In view of the shortcomings derived from the above-mentioned conventional technologies, the inventors of the present invention have improved and innovated, and after years of painstaking research, they finally succeeded in research and development of the IP network traffic error detection and analysis system. Using Cloud Computing's "distributed computing" concept, the huge computing operations are broken into thousands of smaller jobs and operated simultaneously on remote and multi-servers.

本發明目的是在提供IP網路訊務分散式佈點、集中管控之訊務查錯與分析系統,能夠分別針對P2P訊務、DDoS攻擊、VoIP訊務、L7通訊協定、與訊務QoS等訊務資料作個別即時分析與檢測。The object of the present invention is to provide an IP network traffic distributed distributed point, centralized control and traffic error detection and analysis system, which can respectively target P2P communication, DDoS attack, VoIP communication, L7 communication protocol, and traffic QoS. Information for individual analysis and testing.

可達成上述發明目的之IP網路訊務查錯與分析系統,此系統包含分散式探測器(DP)與伺服器主機群等兩大子系統所組成。伺服器主機群包含網站伺服器、資料庫伺服器、即時訊務複製重現伺服器(RIDS)、訊務分析設備模組與報表伺服器模組。即時訊務複製重現伺服器(RIDS)與訊務分析設備模組,運用Cloud Computing的架構,當IP網路訊務由分散式探測器(DP)子系統收集,並導入RIDS設備後,可進一步導入多種訊務分析設備模組,分別能夠針對P2P訊務、DDoS攻擊、VoIP訊務、L7通訊協定、與訊務QoS等訊務資料作個別即時分析與檢測。每一模組之分析設備分別是由3~ 5台不同的訊務分析設備組成;將訊務資料分析過後,分別傳送到各模組之專用報表伺服器。針對5種不同的訊務分析,使用不同的訊務分析設備模組,搭配模組化即時處理訊務之軟體(3~ 5種)進行訊務查錯與分析。The IP network traffic error detection and analysis system can achieve the above object, and the system comprises two subsystems: a distributed detector (DP) and a server host group. The server host group includes a website server, a database server, an instant message replication and replay server (RIDS), a traffic analysis device module, and a report server module. Instant Messaging Reproducing Server (RIDS) and Traffic Analysis Device Modules, using Cloud Computing architecture, when IP network traffic is collected by the Decentralized Detector (DP) subsystem and imported into the RIDS device, Further importing a variety of traffic analysis device modules, respectively, for individual P2P traffic, DDoS attacks, VoIP traffic, L7 communication protocols, and traffic QoS and other traffic data for individual analysis and detection. The analysis equipment of each module is composed of 3 ~ 5 different traffic analysis devices; after analyzing the traffic data, it is transmitted to the dedicated report server of each module. For 5 different traffic analysis, different traffic analysis device modules are used, combined with modular instant processing software (3 ~ 5) for traffic troubleshooting and analysis.

請參閱圖一,為本發明IP網路訊務查錯與分析系統之系統架構圖,由圖中可知,本發明是由分散式探測器(DP)11與伺服器主機群12等兩大子系統所組成,分別負責網路上各個節點之間訊務的收集檢測、深層分析與人機界面等功能。其中分散式探測器(DP)11係架設於各IP骨幹網路(IP backbone)上各個節點,而伺服器主機群12則透過網路連接IP骨幹網路上的其中一個節點,達成集中控管與分析各IP骨幹網路的訊務之功能。Please refer to FIG. 1 , which is a system architecture diagram of an IP network traffic error detection and analysis system according to the present invention. As can be seen from the figure, the present invention is composed of a distributed detector (DP) 11 and a server host group 12 . The system is composed of functions responsible for collection, detection, deep analysis and human-machine interface of each node on the network. The distributed detector (DP) 11 is installed on each node of each IP backbone network, and the server host group 12 is connected to one of the nodes on the IP backbone network through the network to achieve centralized control and Analyze the functions of the traffic of each IP backbone network.

本發明之分散式探測器11,在硬體部分需採用與一般商用PC架構同等之擴充性,穩定度須更為可靠,足以應付長時間不停機工作要求之電腦平台;在軟體部分需採用具有操作穩定、同時允許多人多工上線與相對比較不耗資源的作業系統。目前分散式探測器11主要的功能為即時網路訊務監測與擷取功能,其通常是放置於網路的邊緣路由器(Edge Router)或客戶終端(Customer End),透過路由(或交換)器的複製埠(Mirror Port)或網路分接器(Tap)來達到訊務擷取與監測之目的。The distributed detector 11 of the present invention needs to adopt the same expandability as the general commercial PC architecture in the hardware part, and the stability must be more reliable, and it is sufficient for the computer platform that requires long-term non-stop work; Operational system that is stable in operation and allows multiple people to go online and relatively less resource-intensive. At present, the main function of the distributed detector 11 is the instant network traffic monitoring and retrieval function, which is usually placed on the edge router (Customer End) of the network or through the routing (or switching) device. Mirror Port or Tap to achieve traffic capture and monitoring.

本發明之伺服器主機群12,係由網站伺服器13、資料庫伺服器14與即時訊務複製重現伺服器(RIDS)15、訊務分析設備模組(AS)16以及報表伺服器模組17所組成。其中該網站伺服器13,主要提供人機操作界面以便檢視分散式探測器11狀態、設定並控制整體設備以便分析IP網路訊務之第四層至第七層資訊。資料庫伺服器14則負責儲存封包擷取資料。RIDS 15則將資料庫伺服器14之封包擷取資料導入多種訊務分析設備模組16,能夠同步的快速分析網路訊務並針對制定的政策來啟動告警。而報表伺服器模組17則負責輸出各訊務分析設備模組16最後所產生的檢測結果,包括網路的各類封包分析報表,內容包含P2P訊務、DDoS攻擊、VoIP訊務、L7通訊協定、與訊務QoS之分析與查錯等。The server host group 12 of the present invention is composed of a website server 13, a database server 14, an instant message copy and reproduce server (RIDS) 15, a traffic analysis device module (AS) 16, and a report server module. Group 17 consists of. The website server 13 mainly provides a human-machine operation interface for viewing the status of the distributed detector 11 and setting and controlling the overall device for analyzing the fourth layer to the seventh layer information of the IP network communication. The database server 14 is responsible for storing the packet retrieval data. The RIDS 15 then imports the packet retrieval data from the database server 14 into a plurality of traffic analysis device modules 16, which can quickly analyze the network traffic and initiate an alarm for the established policy. The report server module 17 is responsible for outputting the final detection results generated by each of the traffic analysis device modules 16, including various packet analysis reports of the network, including P2P services, DDoS attacks, VoIP services, and L7 communication. Agreement, analysis and troubleshooting of traffic QoS.

請參閱圖二,為本發明IP網路訊務查錯與分析系統之分散式探測器與伺服器主機群間的功能架構圖,由圖中可知,其中該分散式探測器11,藉由網路訊務即時監測模組(Network Monitoring,NM),即時收集網路訊務資料,並可利用FTP(File Transfer Protocol)協定方式傳回伺服器主機群12。負責人機界面的網站伺服器13採用PHP(Hypertext Preprocessor)、Perl以及Java程式語言來撰寫動態網頁,並利用權限管理機制,將具備設定RIDS 15以及訊務分析設備模組16功能之人員、線上查詢人員以及輸出報表資料的人員進行控管。Please refer to FIG. 2 , which is a functional architecture diagram of a distributed detector and a server host group of the IP network traffic error detection and analysis system of the present invention. It can be seen from the figure that the distributed detector 11 is Network Monitoring (NM) monitors network traffic data in real time and can be sent back to server host group 12 by FTP (File Transfer Protocol) protocol. The web server 13 responsible for the human-machine interface uses a PHP (Hypertext Preprocessor), Perl, and Java programming language to compose a dynamic web page, and uses a rights management mechanism to have a person who has the functions of setting the RIDS 15 and the traffic analysis device module 16, online. The inspector and the person who outputs the report data are controlled.

請參閱圖三,為本發明IP網路訊務查錯與分析系統之主動測試模組測試架構圖,由圖中可知,包含集中管理系統18(即是伺服器主機群12)及架設於骨幹網路各節點之分散式探測器11二個部分。其中該集中管理系統18負責收集由分散式探測器11所收集之資料,傳送至RIDS 15核心元件產生複製備份的訊務資料,並即時分配傳送到各訊務分析設備模組16加以分析,並將結果由各分析設備的報表伺服器模組17,回報到使用者端,可依據收到的回報資訊定期產生報表。此外提供客戶端網路使用者介面,可隨時進入系統觀察網路狀況;該分散式探測器11可即時收集客戶端的IP流量,並將訊務資訊傳送到RIDS 15核心元件,並複製分配至分析設備模組,作即時性的網路訊務分析與查錯。Please refer to FIG. 3 , which is a test architecture diagram of an active test module of the IP network traffic error detection and analysis system of the present invention. It can be seen from the figure that the centralized management system 18 (that is, the server host group 12 ) and the backbone are installed. Two parts of the distributed detector 11 of each node of the network. The centralized management system 18 is responsible for collecting the data collected by the distributed detector 11, and transmitting the data to the core component of the RIDS 15 to generate the duplicated backup data, and transmitting the data to the traffic analysis device module 16 for analysis. The result is reported to the user end by the report server module 17 of each analysis device, and the report can be periodically generated according to the received return information. In addition, a client network user interface is provided, and the system can be observed at any time to observe the network status; the distributed detector 11 can instantly collect the IP traffic of the client, and transmit the traffic information to the core component of the RIDS 15, and copy and distribute the analysis to the analysis. Device module for instant network traffic analysis and troubleshooting.

請參閱圖四,為本發明IP網路訊務查錯與分析系統之RIDS與訊務分析設備模組整合測試架構圖,由圖中可知,使用Cloud Computing的架構,其中該訊務分析設備模組16包含P2P Analyzer模組、DDoS Analyzer模組、VoIP Analyzer模組、L7 Protocol Analyzer模組及網路QoS Analyzer模組等5種分析模組,分別針對P2P訊務、DDoS攻擊、VoIP訊務、L7通訊協定、與網路QoS等訊務資料作分析與查錯。每一模組分別是由3~ 5台不同的訊務分析設備19組成,將訊務資料分析過後,分別傳送到各模組之專用報表伺服器20。本發明可針對不同的訊務,使用不同的訊務分析設備,予以即時處理分析。當網路訊務產生異常狀態時,能夠針對各模組特性進行同步分析並偵測問題的所在,並傳送警告訊息至報表伺服器20,可幫助使用者在不同的設定與不同的網路條件下,預測應用程式的效能。當報表伺服器20接收到超過網路安全臨界標準值時,便即時傳送異常回報資訊至網管中心。Please refer to FIG. 4 , which is an architecture diagram of the integration test of the RIDS and the traffic analysis device module of the IP network traffic error detection and analysis system of the present invention. It can be seen from the figure that the architecture of the Cloud Computing is used, wherein the traffic analysis device module Group 16 includes five analysis modules, such as P2P Analyzer module, DDoS Analyzer module, VoIP Analyzer module, L7 Protocol Analyzer module and network QoS Analyzer module, for P2P services, DDoS attacks, VoIP services, L7 communication protocol, and network QoS and other traffic data for analysis and troubleshooting. Each module is composed of 3 to 5 different traffic analysis devices 19, and the traffic data is analyzed and transmitted to the dedicated report server 20 of each module. The invention can be processed and analyzed in real time by using different traffic analysis devices for different services. When the network traffic generates an abnormal state, it can perform synchronous analysis and detect the problem for each module feature, and send a warning message to the report server 20, which can help the user in different settings and different network conditions. Next, predict the performance of the application. When the report server 20 receives the network security critical standard value, it immediately transmits the abnormal return information to the network management center.

本發明之訊務分析設備模組16,包含P2P Analyzer模組、DDoS Analyzer模組、VoIP Analyzer模組、L7 Protocol Analyzer模組及網路QoS Analyzer模組等5種分析模組,其中P2P Analyzer模組能夠針對P2P訊務進行深層分析,並且監測網路訊務中的P2P應用程式或P2P網路協議佔用多少頻寬,不僅幫助管理人員對整體網路流量的傳輸情況進行了解,也對訊務進行統計分析。透過RIDS 15,訊務可以針對特定應用服務、特定網路協定作上鏈路或下鏈路的訊務來進行進一步的P2P深層分析。The traffic analysis device module 16 of the present invention comprises five kinds of analysis modules, such as a P2P Analyzer module, a DDoS Analyzer module, a VoIP Analyzer module, an L7 Protocol Analyzer module and a network QoS Analyzer module, among which P2P Analyzer modules The group can perform deep analysis on P2P traffic and monitor how much bandwidth the P2P application or P2P network protocol in the network traffic occupies, which not only helps the administrator to understand the transmission of the overall network traffic, but also the traffic. conduct statistical analysis. Through RIDS 15, traffic can perform further P2P deep analysis for specific application services, specific network protocols for uplink or downlink traffic.

而該DDoS Analyzer模組,能夠針對DoS攻擊的手法,包括TCP(Transmission Control Protocol)DoS攻擊、UDP(User Datagram Protocol)Flood DoS攻擊、DDoS攻擊、以及ICMP(Internet Control Message Protocol)DoS攻擊等,同步即時監控區域網路中的封包數量是否異常,並配合動態封包過濾,以便達到防禦DoS攻擊的目的。當攻擊發生時即時將警告訊息透過回報伺服器回傳至網路管理者。The DDoS Analyzer module can be used for the DoS attack, including the TCP (Transmission Control Protocol) DoS attack, the UDP (User Datagram Protocol) Flood DoS attack, the DDoS attack, and the ICMP (Internet Control Message Protocol) DoS attack. Instantly monitor whether the number of packets in the local area network is abnormal, and cooperate with dynamic packet filtering to achieve the purpose of defending against DoS attacks. When the attack occurs, the warning message is immediately transmitted back to the network administrator through the reward server.

該VoIP Analyzer模組,則針對SIP(Session Initiation Protocol)、H.232、MGCP(Media Gateway Control Protocol)等多種協定進行分析,並可針對VoIP語音與視訊進行定量測量。VoIP分析模組將每個電話呼叫進行詳細的統計分析,讓網路維護者可以掌握網路中VoIP通訊的品質。The VoIP Analyzer module analyzes various protocols such as SIP (Session Initiation Protocol), H.232, and MGCP (Media Gateway Control Protocol), and can perform quantitative measurement for VoIP voice and video. The VoIP Analysis Module performs detailed statistical analysis of each phone call, allowing network maintainers to grasp the quality of VoIP communications in the network.

該L7 Protocol Analyzer模組,為第七層網路分析工具,利用「深度封包檢測」(Deep Packet Inspection,DPI)技術針對欲分析之網路流量,執行即時檢測並加以分類;並將網路的QoS參數實際透過Delay、Jitter等網路效能參數值表現出來,以及結合報表伺服器20達成告警動作;精細的統計數據則會利用報表軟體在伺服器上整理成完整、有用的網路報表。透過報表的顯示,可以清楚了解網路訊務的應用程式分布狀態,讓網路維護者方便檢測網路環境的各種問題,並且預測未來新網路服務的規劃所需要的趨勢。The L7 Protocol Analyzer module is a Layer 7 network analysis tool that uses Deep Packet Inspection (DPI) technology to perform on-the-spot detection and classification of network traffic to be analyzed; The QoS parameters are actually displayed through the network performance parameter values such as Delay and Jitter, and the alarm action is achieved in conjunction with the report server 20; the fine statistics are compiled into a complete and useful network report on the server by using the report software. Through the display of reports, you can clearly understand the application distribution status of network traffic, so that network maintainers can easily detect various problems in the network environment and predict the trends required for the planning of new network services in the future.

該網路QoS Analyzer模組,乃提供網路品質狀況的即時偵測,主要針對封包遺失,傳送延遲,封包傳送順序,以及其他錯誤的即時監控。例如,當網路壅塞而造成傳送延遲大幅增加,或者發生封包大量遺失等狀況時,本分析模組可以偵測此類異常狀況。本分析模組與報表伺服器20整合後,可將各類QoS訊息傳送至管理者端,並且在超過異常臨界值之前預先發出警告,可即時掌握網路的QoS狀態。此外,透過本模組也可以檢視長期的網路流量圖表,進而加以分析以推估未來流量的趨勢。The network QoS Analyzer module provides instant detection of network quality conditions, mainly for packet loss, transmission delay, packet transmission sequence, and other error monitoring. For example, when the network congestion causes a large increase in transmission delay, or a large number of packets are lost, the analysis module can detect such abnormal conditions. After the analysis module is integrated with the report server 20, various types of QoS messages can be transmitted to the manager, and a warning is issued before the abnormal threshold is exceeded, so that the QoS status of the network can be instantly grasped. In addition, this module can also view long-term network traffic graphs and analyze them to estimate future traffic trends.

本發明所提供之IP網路訊務查錯與分析系統,與其他習用技術相互比較時,更具備下列優點:The IP network traffic error detection and analysis system provided by the present invention has the following advantages when compared with other conventional technologies:

1.運用本發明之IP網路訊務查錯與分析系統,具有即時檢測功能,能夠檢視、量測、收集IP網路之穩定性及可靠性等相關數據,作為目前網路效能檢測、診斷、模擬、以及未來流量成長的預測等之依據。1. Using the IP network traffic error detection and analysis system of the present invention, with instant detection function, capable of inspecting, measuring and collecting related data such as stability and reliability of the IP network, as current network performance detection and diagnosis , simulation, and prediction of future traffic growth.

2.本發明之IP網路訊務查錯與分析系統,可提供IP網路各類型檢測服務,如企業網路安全與效能健檢等。2. The IP network traffic error detection and analysis system of the present invention can provide various types of detection services for IP networks, such as enterprise network security and performance health check.

3.擷取流經網路上的封包記錄及應用程序的資料交換情形,用來模擬建構真實網路流量,並加以分析診斷網路層,應用層間的程序活動。3. Capture the packet exchange records and application data exchange scenarios on the network to simulate the construction of real network traffic, and analyze and diagnose the network layer, application layer program activity.

4.自行整合多合一功能的標準型探測器之量測設備(DP)與即時訊務複製重現伺服器(RIDS),大幅降低建置服務成本。4. Self-integration of all-in-one standard detectors (DP) and Instant Messaging Reproducing Server (RIDS), significantly reducing the cost of installation services.

5.本發明之運用Cloud Computing技術實作IP網路訊務分散式佈點、集中管控之訊務查錯與分析系統也適用於IP網路無人機房,配合網管系統,達到即時維運效果。也可配合SOC(Security Operating Center)系統,達到網路訊務即時分析與查錯。5. The use of the Cloud Computing technology to implement the IP network traffic distributed layout, centralized control and traffic error detection and analysis system is also applicable to the IP network unmanned computer room, with the network management system, to achieve instant maintenance effect. It can also be used with the SOC (Security Operating Center) system to achieve real-time analysis and troubleshooting of network traffic.

6.本發明可分別針對P2P訊務、DDoS攻擊、VoIP訊務、L7通訊協定、與訊務QoS等訊務資料作個別即時分析與檢測。6. The present invention can perform individual real-time analysis and detection on P2P traffic, DDoS attacks, VoIP services, L7 communication protocols, and traffic QoS.

上列詳細說明係針對本發明之一可行實施例之具體說明,惟該實施例並非用以限制本發明之專利範圍,凡未脫離本發明技藝精神所為之等效實施或變更,均應包含於本案之專利範圍中。The detailed description of the preferred embodiments of the present invention is intended to be limited to the scope of the invention, and is not intended to limit the scope of the invention. The patent scope of this case.

綜上所述,本案不但在技術思想上確屬創新,並能較習用物品增進上述多項功效,應以充分符合新穎性及進步性之法定發明專利要件,爰依法提出申請,懇請 貴局核准本件發明專利申請案,以勵發明,至感德便。To sum up, this case is not only innovative in terms of technical thinking, but also able to enhance the above-mentioned multiple functions compared with conventional articles. It should be submitted in accordance with the law in accordance with the statutory invention patents that fully meet the novelty and progressiveness, and you are requested to approve this article. Invention patent application, in order to invent invention, to the sense of virtue.

11...分散式探測器11. . . Decentralized detector

12...伺服器主機群12. . . Server host group

13...網站伺服器13. . . Website server

14...資料庫伺服器14. . . Database server

15...即時訊務複製重現伺服器15. . . Instant messaging replication server

16...訊務分析設備模組16. . . Traffic Analysis Device Module

17...報表伺服器模組17. . . Report server module

18...集中管理系統18. . . Centralized management system

19...訊務分析設備19. . . Traffic analysis equipment

20...報表伺服器20. . . Report server

圖一為本發明IP網路訊務查錯與分析系統之系統架構圖;FIG. 1 is a system architecture diagram of an IP network traffic error detection and analysis system according to the present invention; FIG.

圖二為該IP網路訊務查錯與分析系統之分散式探測器與伺服器主機群間的功能架構圖;Figure 2 is a functional architecture diagram of the decentralized detector and server host group of the IP network traffic error detection and analysis system;

圖三為該IP網路訊務查錯與分析系統之主動測試模組測試架構圖;Figure 3 is a test architecture diagram of the active test module of the IP network traffic error detection and analysis system;

圖四為該IP網路訊務查錯與分析系統之即時訊務複製重現伺服器與訊務分析設備整合測試架構圖。Figure 4 is an integrated test architecture diagram of the instant messaging replication server and the traffic analysis device of the IP network traffic error detection and analysis system.

11...分散式探測器11. . . Decentralized detector

12...伺服器主機群12. . . Server host group

13...網站伺服器13. . . Website server

14...資料庫伺服器14. . . Database server

15...即時訊務複製重現伺服器15. . . Instant messaging replication server

16...訊務分析設備模組16. . . Traffic Analysis Device Module

17...報表伺服器模組17. . . Report server module

Claims (10)

一種IP網路訊務查錯與分析系統,至少包含:一分散式探測器(Distributed Probe,DP)子系統,包含複數個分散式探測器,分別架設於各IP骨幹網路(IP backbone)上各個節點,主要係負責網路上各個節點之間訊務的收集檢測、深層分析與人機界面等功能;一網站伺服器,提供人機操作界面,以檢視分散式探測器狀態、設定,並控制整體設備以分析IP網路訊務資料;一資料庫伺服器,藉由網站伺服器連接IP骨幹網路上的其中一個節點,以儲存分散式探測器擷取之訊務資料;一即時訊務複製重現伺服器(RIDS),將資料庫伺服器儲存之訊務資料產生複製備份資料,並即時分配傳送到各訊務分析設備模組;一訊務分析設備模組,包含不同訊務資料的分析設備,與即時訊務複製重現伺服器以Cloud Computing的架構連接,可個別即時分析與檢測不同的訊務資料;一報表伺服器模組,包含分別連接訊務分析設備模組之各分析設備之報表輸出設備,可分別輸出不同的訊務資料之分析與查錯報表。An IP network traffic error detection and analysis system includes at least a distributed probe (DP) subsystem, which includes a plurality of distributed detectors, which are respectively installed on IP backbones (IP backbones). Each node is mainly responsible for the collection, detection, deep analysis and human-machine interface of the traffic between the nodes on the network; a web server provides a human-machine interface to view the status, settings, and control of the distributed detectors. The whole device analyzes the IP network traffic data; a database server connects one of the nodes on the IP backbone network through the web server to store the traffic data captured by the distributed detector; an instant message replication Reproducing server (RIDS), generating copy backup data from the data stored in the database server, and distributing it to each traffic analysis device module in real time; a traffic analysis device module containing different traffic data The analysis device is connected with the instant messaging replication server in the Cloud Computing architecture, and can analyze and detect different traffic data in real time; a report server module, The report output device including each analysis device connected to the traffic analysis device module can respectively output different analysis and error check reports of the traffic data. 如申請專利範圍第1項所述之IP網路訊務查錯與分析系統,其中該分散式探測器子系統,係放置於網路的邊緣路由器(Edge Router)或客戶終端(Customer End),透過路由(或交換)器的複製埠(Mirror Port)或網路分接器(Tap)來達到訊務擷取與監測之目的,並可利用FTP協定方式將收集到之即時網路訊務資料傳回資料庫伺服器儲存。The IP network traffic error detection and analysis system described in claim 1, wherein the distributed detector subsystem is placed on an edge router or a customer terminal of the network. Through the routing (or switch) Mirror Port or network tap (Tap) to achieve the purpose of traffic retrieval and monitoring, and can use the FTP protocol to collect the collected real-time network traffic data Return to the database server for storage. 如申請專利範圍第1項所述之IP網路訊務查錯與分析系統,其中該訊務分析設備模組,分析之訊務資料,可包含P2P訊務、DDoS攻擊、VoIP訊務、L7通訊協定、與網路QoS等訊務資料。For example, the IP network traffic error detection and analysis system described in claim 1 wherein the traffic analysis device module analyzes the traffic information, which may include P2P traffic, DDoS attacks, VoIP services, and L7. Communication data such as communication protocols and network QoS. 如申請專利範圍第1項所述之IP網路訊務查錯與分析系統,其中該訊務分析設備模組之分析設備,可包含P2P Analyzer模組、DDoS Analyzer模組、VoIP Analyzer模組、L7 Protocol Analyzer模組、與網路QoS Analyzer模組等分析設備。For example, the IP network traffic error detection and analysis system described in the first application of the patent scope, wherein the analysis device of the traffic analysis device module may include a P2P Analyzer module, a DDoS Analyzer module, a VoIP Analyzer module, Analysis equipment such as the L7 Protocol Analyzer module and the network QoS Analyzer module. 如申請專利範圍第4項所述之IP網路訊務查錯與分析系統,其中該P2P Analyzer模組,可監測網路訊務中的P2P應用程式或P2P網路協議佔用多少頻寬,以及透過RIDS,可以針對特定應用服務、特定網路協定作上鏈路或下鏈路的訊務P2P深層分析。For example, the IP network traffic error detection and analysis system described in claim 4, wherein the P2P Analyzer module can monitor the bandwidth occupied by the P2P application or the P2P network protocol in the network service, and Through RIDS, you can perform deep P2P analysis of traffic on the uplink or downlink for specific application services and specific network protocols. 如申請專利範圍第4項所述之IP網路訊務查錯與分析系統,其中該DDoS Analyzer模組,可以透過分析設備上多個網路監控程式,同步即時監控區域網路中的封包數量是否異常,並配合動態封包過濾功能,來防禦DoS的攻擊。For example, the IP network traffic error detection and analysis system described in claim 4, wherein the DDoS Analyzer module can synchronously monitor the number of packets in the local area network by analyzing multiple network monitoring programs on the device. Whether it is abnormal and cooperate with dynamic packet filtering to defend against DoS attacks. 如申請專利範圍第6項所述之IP網路訊務查錯與分析系統,其中該DoS攻擊可包括TCP(Transmission Control Protocol)DoS攻擊、UDP(User Datagram Protocol)Flood DoS攻擊、DDoS攻擊、以及ICMP(Internet Control Message Protocol)DoS攻擊等。The IP network traffic error detection and analysis system described in claim 6 , wherein the DoS attack may include a TCP (Transmission Control Protocol) DoS attack, a UDP (User Datagram Protocol) Flood DoS attack, a DDoS attack, and ICMP (Internet Control Message Protocol) DoS attack. 如申請專利範圍第4項所述之IP網路訊務查錯與分析系統,其中該VoIP Analyzer模組,可針對SIP、H.232、MGCP等多種協定進行分析,以及對VoIP語音與視訊進行定量測量。For example, the IP network traffic error detection and analysis system described in claim 4, wherein the VoIP Analyzer module can analyze various protocols such as SIP, H.232, MGCP, and perform VoIP voice and video. Quantitative measurement. 如申請專利範圍第4項所述之IP網路訊務查錯與分析系統,其中該L7 Protocol Analyzer模組,係利用深度封包檢測(DPI)技術針對欲分析之網路流量,執行即時檢測並加以分類;能夠將網路的QoS參數實際透過Delay、Jitter等網路效能參數值表現出來,以清楚了解網路訊務的應用程式分布狀態。The IP network traffic error detection and analysis system described in claim 4, wherein the L7 Protocol Analyzer module performs deep detection by using Deep Packet Inspection (DPI) technology for network traffic to be analyzed. It can be classified; the QoS parameters of the network can be actually expressed through the network performance parameter values such as Delay and Jitter, so as to clearly understand the application distribution state of the network traffic. 如申請專利範圍第4項所述之IP網路訊務查錯與分析系統,其中該網路QoS Analyzer模組,係提供網路品質狀況的即時偵測功能,主要係針對封包遺失,傳送延遲,封包傳送順序,以及其他錯誤來即時監控,可即時掌握網路的QoS狀態。For example, the IP network traffic error detection and analysis system described in claim 4, wherein the network QoS Analyzer module provides real-time detection of network quality status, mainly for packet loss, transmission delay. , packet transmission sequence, and other errors for real-time monitoring, you can instantly grasp the QoS status of the network.
TW98125298A 2009-07-28 2009-07-28 IP network traffic error detection and analysis system TWI389504B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW98125298A TWI389504B (en) 2009-07-28 2009-07-28 IP network traffic error detection and analysis system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW98125298A TWI389504B (en) 2009-07-28 2009-07-28 IP network traffic error detection and analysis system

Publications (2)

Publication Number Publication Date
TW201105065A TW201105065A (en) 2011-02-01
TWI389504B true TWI389504B (en) 2013-03-11

Family

ID=44813867

Family Applications (1)

Application Number Title Priority Date Filing Date
TW98125298A TWI389504B (en) 2009-07-28 2009-07-28 IP network traffic error detection and analysis system

Country Status (1)

Country Link
TW (1) TWI389504B (en)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TW201351926A (en) * 2012-06-06 2013-12-16 Chunghwa Telecom Co Ltd Performance monitoring and sampling system for backbone network
TW201351171A (en) * 2012-06-08 2013-12-16 Cobrasonic Software Inc Network packet and database packet auditing system and related auditing device and method
TW201404074A (en) * 2012-07-02 2014-01-16 Chunghwa Telecom Co Ltd Fault diagnosis method by wideband network traffic analysis using relational rules

Also Published As

Publication number Publication date
TW201105065A (en) 2011-02-01

Similar Documents

Publication Publication Date Title
Cui et al. SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks
US7804787B2 (en) Methods and apparatus for analyzing and management of application traffic on networks
US8095635B2 (en) Managing network traffic for improved availability of network services
Garrett et al. Monitoring network neutrality: A survey on traffic differentiation detection
CN100356733C (en) Recording medium, fault analysis device and fault analysis method
CN101567814B (en) Automatic network management method based on SNMP and stochastic Petri net
WO2003084134A1 (en) Systems and methods for end-to-end quality of service measurements in a distributed network environment
WO2019006008A1 (en) Apparatus and method for monitoring network performance of virtualized resources
Alkenani et al. Network monitoring measurements for quality of service: a review
Dainotti et al. A packet-level characterization of network traffic
TWI389504B (en) IP network traffic error detection and analysis system
CN105357071B (en) A kind of network complexity method for recognizing flux and identifying system
Duman et al. Performance metrics and monitoring tools for sustainable network management
Freire et al. On metrics to distinguish skype flows from http traffic
Wilailux et al. Novel bi-directional flow-based traffic generation framework for ids evaluation and exploratory data analysis
TW201038009A (en) Real-time traffic measurement system of IP network centralized network management and distributed nodes
Rosa et al. Abnormal internet usage detection in LAN Islamic University of Riau Indonesia
Nobre et al. Coordination in P2P management overlays to improve decentralized detection of SLA violations
Viipuri Traffic analysis and modeling of IP core networks
Xia et al. Cids: Adapting legacy intrusion detection systems to the cloud with hybrid sampling
CN118573583B (en) A cyberspace asset mapping method for power monitoring system
Eittenberger et al. Atheris: A First Step Towards a Uni? ed Peer-to-Peer Traf? c Measurement Framework
Salem et al. Transforming voluminous data flow into continuous connection vectors for IDS
Padovan et al. DDoSGrid 3.0: Enabling the Real-time Processing and Analysis of Cyber Attacks Traffic
Rochim et al. Design and Implementation of Post-Detection of Denial of Service (DoS) as a Mitigation System (PDDMS) Based on Dynamic Access Control List Algorithm

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees