摘要:
A distributed system for analyzing traffic flow on a communications network architecture where a computer provides information over a data network to a concentrator, which provides a bridge between the computer and the end user terminals. The interface between the terminals and the concentrator is provided through access points for each workstation. The system to analyze the traffic is distributed into three components that perform, respectively, classification of the traffic flow, processing of the results of the classification, and handling of the processed results.
摘要:
The present invention provides a traffic analyzing system on a communications link having analyzer circuits connected to each other by a number of links, where each analyzer circuit has a data rate lower than the data rate of the communications link, and are adapted to perform respective different levels of analysis on packets. The information extracted from the packets analyzed at a first level of analysis by a first analyzer circuit is forwarded to a second level of analysis performed at a second analyzer circuit, where the additional analysis performed by the second analyzer circuit depends on the analysis performed by the first analyzer circuit. Such a system and associated method allows for an efficient, practical, and improved traffic flow analyses for computer networks to evaluate high-speed and heavy traffic flow, as well as for improved protocol analysis for emerging technologies.
摘要:
A distributed system for analyzing traffic flow on a communications network architecture where a computer provides information over a data network to a concentrator, which provides a bridge between the computer and the end user terminals. The interface between the terminals and the concentrator is provided through access points for each workstation. The system to analyze the traffic is distributed into three components that perform, respectively, classification of the traffic flow, processing of the results of the classification, and handling of the processed results.
摘要:
The invention relates to a data collection device for monitoring streams in a data network using a packet transmission mode, including an extractor for extracting data contained in packets belonging to a stream defined by a transmitter, a receiver, and a protocol. The collection device also includes a syntax analyzer which receives data in real time from the extractor and breaks the data down into elements according to the syntactic rules of the protocol, said syntactic rules enabling the elements to be represented as a tree structure. The syntax analyzer combines respective tree state indicators with at least some of the elements, wherein the tree state indicator combined with an element locates said element within the tree structure. An interface transmits the tree state indicators, together with the elements with which the latter have been combined, to a stream analyzer external to the collection device.
摘要:
The present invention provides a traffic analyzing system on a communications link having analyzer circuits connected to each other by a number of links, where each analyzer circuit has a data rate lower than the data rate of the communications link, and are adapted to perform respective different levels of analysis on packets. The information extracted from the packets analyzed at a first level of analysis by a first analyzer circuit is forwarded to a second level of analysis performed at a second analyzer circuit, where the additional analysis performed by the second analyzer circuit depends on the analysis performed by the first analyzer circuit. Such a system and associated method allows for an efficient, practical, and improved traffic flow analyses for computer networks to evaluate high-speed and heavy traffic flow, as well as for improved protocol analysis for emerging technologies.
摘要:
The method uses a network for protocol self identification for recognizing determinative data by the naming given among data transmitted through a detected connection, and an empty or nonempty list of protocol usable namings called son protocols associated with each usable protocol naming called a father protocol. The kernel of an information system associates to each detected connection a data structure arranged so that it comprises an ordered sequence of the used protocol namings. The kernel builds the data structure by retrieving the son protocol namings in the list associated to the last naming of said ordered sequence, the son protocol naming for which the associated self identification mechanism recognizes determinant data among transmitted data by adding the retrieved son protocol naming to the end of the sequence and by restarting to retrieve the son protocol naming for which the associated self identification mechanism recognizes determinant data among transmitted data.
摘要:
The invention relates to a method for supervising a communication session over a data network, said session including a first data flow, referred to as the parent flow, using a first protocol, said parent flow including data suitable for setting up a second data flow, referred to as the child flow, using a second protocol for said session, which includes: searching (13) the parent flow for the data that enable the child flow to be set up; generating (15) and storing (17) a signature, referred to as a parent key, using said data; auditing (19) data flows using the second protocol on the data network; creating (21) a signature for each one of the flows; comparing (23) said signature of each one of the flows with the parent key; and, if the comparison is positive, determining (25) that the data flow in question is the child flow of the session.
摘要:
A method for protocol identification by recognizing determinative data among data transmitted through a detected connection using lists of explicit and implicit son protocols associated with each protocol. The kernel of an information system associates to each detected connection a data structure arranged so that it comprises an ordered sequence of the protocol names. The kernel builds the data structure by retrieving the son protocol names in the list associated to the last protocol name of said ordered sequence, the son protocol name for which the associated self identification mechanism recognizes determinant data among transmitted data by adding the retrieved son protocol name to the end of the sequence and by restarting to retrieve the son protocol name for which the associated self identification mechanism recognizes determinant data among transmitted data.
摘要:
The invention concerns a digital processing system fed by at least one filter having three possible states resulting from one or more conditions on one or more protocol attributes, specified for a semantic stream. Each protocol attribute is specified by an ordered sequence of protocol names used in the semantic stream and a parameter name carried by a protocol whereof the name is indicated in the ordered sequence of protocol names. The digital processing device comprises a filtering engine which applies the filter on the communication data until the data provide protocol attribute values wherefrom results a valid or invalid state of the filter and an action motor which triggers the action when the state of the filter is valid.