A kind of network audit equipment and method based on the traffic statistics network interface card
Technical field
The invention belongs to the network data processing field, be specifically related to a kind of network audit equipment and method based on the traffic statistics network interface card.
Background technology
Network auditing system equipment is meant the equipment that IDS etc. audits to network traffics and content, and this kind equipment need be discerned the content of various types of message characteristics and Network Transmission in the network traffics, statistics and analysis.General express network audit equipment comprises two parts function, and a part is basic traffic statistics, and such as the flow counting of certain port, ip, agreement, another part is the analysis to the network data content.Wherein, the data that the former processing procedure simple fixation, but need to handle all data, latter's complex disposal process but need are handled are less.In the applied environment of express network, network audit requires very high to equipment performance.
The patent No. " CN200610124026.2 " denomination of invention is " a kind of method and system of network flow statistic "; A kind of statistical method of network traffics is disclosed; Comprise: network traffics are subscribed to equipment and are sent sip subscribe message to network flow statistic equipment, and network traffics pull subscription; Network flow statistic equipment carries out network flow statistic according to the said sip subscribe message that receives; Network flow statistic equipment returns to network traffics through the SIP notification message with the network flow statistic result and subscribes to equipment.The invention also discloses a kind of network flow statistic system.Adopt the present invention, make soft switch and sip server can obtain the flow information of sip terminal and WMG easily, thereby make operator for the user corresponding service measures to be provided according to the packet and the signaling traffic of statistics.
The patent No. " CN201110055849.5 " denomination of invention is " a kind of network traffics are confirmed method, device and the network equipment "; Disclose a kind of networking flow and confirmed method, device and the network equipment, in order to solve the problem that prior art can't accurate and effective definite network traffics.This method is gathered data forwarding speed constantly through obtaining each interface in the measurement period at each; And this data forwarding speed that will obtain is saved in the memory space; According to each data forwarding speed of preserving in the memory space, confirm the network traffics of this interface.Each gathers the data forwarding speed of this interface constantly in the measurement period owing to obtain in embodiments of the present invention; According to each data forwarding speed of obtaining; Confirm the network traffics of this interface; Therefore can effectively avoid the short-term burst data, to confirming the influence of network traffics accuracy, thereby improve the accuracy of the network traffics of confirming.
But said system realizes that by network audit software and common hardware common hardware in software, is undertaken the basic traffic statistics and the analysis of data content to all flow collections by software.Because the work of bare flow statistics is that each message all needs, so on express network, the traffic statistics that software is realized need consume a large amount of computational resources, efficient is lower.
Summary of the invention
The present invention overcomes the prior art deficiency, realizes network audit equipment based on the traffic statistics network interface card of special use, improves the efficient of network audit equipment.
The invention provides a kind of network audit equipment based on the traffic statistics network interface card, it comprises network audit software module and traffic statistics network interface card module, and this traffic statistics network interface card module comprises message classification module and counting messages module.
Network audit equipment based on the traffic statistics network interface card provided by the invention, its network audit software module comprises content analysis module and traffic statistics module.
Network audit equipment based on the traffic statistics network interface card provided by the invention, the message classification module of its traffic statistics network interface card module is uploaded to the content analysis module in the network audit software module with the flow that needs carry out content analysis.
Network audit equipment based on the traffic statistics network interface card provided by the invention, its network audit software module comprises the statistic registers module, is used for the data that the stored messages statistical module uploads and passes to the traffic statistics module.
Network audit equipment based on the traffic statistics network interface card provided by the invention, its message classification module is handled message classification according to characteristics such as network interface card ip, port, agreement, length.
Network audit equipment based on the traffic statistics network interface card provided by the invention, its counting messages module are added up according to message characteristic and are upgraded the statistic registers module that can read in the network audit software module.
The present invention also provides a kind of network audit method based on the traffic statistics network interface card, on the hardware chip of said traffic statistics network interface card, realizes message classification and counting messages.
Network audit method based on the traffic statistics network interface card provided by the invention; After input flow rate arrives said traffic statistics network interface card; Handle message classification according to characteristics such as network interface card ip, port, agreement, length; The flow that need carry out content analysis is uploaded to software, needs the data of basic statistics information to pass to the counting messages module.
Network audit method based on the traffic statistics network interface card provided by the invention, said according to message characteristic, in hardware, carry out counting messages, and the statistic registers that can read of update software.
Network audit method based on the traffic statistics network interface card provided by the invention; Network audit software need carry out the network traffics of content analysis from the acquisition of said traffic statistics network interface card; Read the flow statistical information from hardware register simultaneously, software combines to realize comprehensive network audit to both.
The present invention is based on special-purpose traffic statistics network interface card and realize network audit equipment; The traffic statistics network interface card is the hardware network interface card of custom-made; Can in hardware, realize basic classification and statistics to input flow rate; The bare flow statistics supplies software to read through hardware register, and the data that need carry out content analysis just are uploaded to software.
Compared with prior art, beneficial effect of the present invention is: the present invention can promote the performance of network auditing system equipment.
Description of drawings
Fig. 1 is a structural representation of the present invention.
Embodiment
Fig. 1 is a structural representation of the present invention; Comprise network audit software module and traffic statistics network interface card module; This traffic statistics network interface card module comprises message classification module and counting messages module and its network audit software module comprises content analysis module and traffic statistics module and statistic registers module, is used for the data that the stored messages statistical module uploads and passes to the traffic statistics module.
Wherein the message classification module of traffic statistics network interface card module is handled message classification according to characteristics such as network interface card ip, port, agreement, length, and the flow that needs is carried out content analysis is uploaded to the content analysis module in the network audit software module.Wherein the counting messages module is added up according to message characteristic and is upgraded the statistic registers module that can read in the network audit software module.
Implementation method of the present invention and process are following:
(1) realizes message classification and two modules of counting messages on the traffic statistics network interface card hardware chip.
(2) after input flow rate arrives the traffic statistics network interface card; The message classification module is handled message classification according to characteristics such as network interface card ip, port, agreement, length; The flow that need carry out content analysis is uploaded to software, needs the data of basic statistics information to pass to the counting messages module.
(3) the counting messages module is added up in hardware according to message characteristic, and the statistic registers that can read of update software.
(4) content analysis module of the network audit software network traffics that need carry out content analysis from the network interface card acquisition, the traffic statistics module reads the flow statistical information from hardware register, and software combines to realize comprehensive network audit to both.
The present invention is on express network, can promote the performance of network auditing system equipment.
Above embodiment is only in order to technical scheme of the present invention to be described but not to its restriction; Although the present invention has been carried out detailed explanation with reference to the foregoing description; The those of ordinary skill in said field is to be understood that: still can specific embodiments of the invention make amendment or replacement on an equal basis; And do not break away from any modification of spirit and scope of the invention or be equal to replacement, it all should be encompassed in the middle of the claim scope of the present invention.