IP Library Granted Patent US 11,947,507
Granted Patent B2
US 11,947,507 · App. 17/925,230 · Granted Apr 2, 2024

Traffic monitoring device, traffic monitoring method, and traffic monitoring program

Inventors: Hiroyuki Uzawa (Tokyo, JP); Shuhei Yoshida (Tokyo, JP); Namiko Ikeda (Tokyo, JP); Koyo Nitta (Tokyo, JP)
Assignee: Nippon Telegraph and Telephone Corporation
G06F16/22H04L41/0677H04L41/12H04L43/026H04L43/028H04L43/062H04L63/1408H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,947,507
App. No.
17/925,230
Granted
Apr 2, 2024
Kind
B2
Abstract

A traffic monitoring apparatus that monitors traffic of a monitoring target network and includes a statistical information processor that acquires statistical information per specific flow of the traffic, and a packet capture unit that captures a packet of the specific flow, in which the statistical information processor includes a statistical information aggregation unit that aggregates the pieces of statistical information, and a statistical information file generation unit that generates a statistical information file based on the pieces of aggregated statistical information.

Claims (50)

1. A traffic monitoring apparatus configured to monitor traffic of a monitoring target network, the traffic monitoring apparatus comprising:

a memory;

a statistical information processor configured to acquire statistical information per specific flow of the traffic, wherein the statistical information processor includes:

a statistical information aggregation circuit configured to aggregate a plurality of pieces of the statistical information; and

a statistical information file generation circuit configured to generate a statistical information file based on the plurality of pieces of the statistical information aggregated by the statistical information aggregation circuit; and

a packet capture circuit configured to capture a packet of the specific flow, wherein the packet capture circuit includes:

a filter configured to filter the packet of the specific flow; and

a capture file generation circuit configured to generate a capture file using the filtered packet, and

wherein the statistical information file generation circuit is configured to generate the statistical information file in accordance with first time information, the capture file generation circuit is configured to generate the capture file in accordance with second time information, the first time information and the second time information are each supplied by an identical time source, and the statistical information processor, the packet capture circuit, and the identical time source are collectively disposed within a single device.

2. The traffic monitoring apparatus according to claim 1 , wherein the statistical information processor includes:

a rule table configured to record rules corresponding to the specific flow and a capture flag value indicating whether the specific flow is a capture target for each of the rules; and

a flow identification circuit configured to identify the specific flow by comparing a rule of the rules recorded in the rule table with a header of an input packet and notify the filter of the capture flag value of the specific flow, wherein when the capture flag value represents the capture target, the filter transmits a packet of the specific flow that is the capture target to the capture file generation circuit and discards a packet of the specific flow that is not the capture target.

3. The traffic monitoring apparatus according to claim 2 , wherein the statistical information processor includes a failure detection circuit configured to detect a failure in the specific flow based on the plurality of pieces of the statistical information, and wherein the failure detection circuit is further configured to update the capture flag value in the rule table of the specific flow where failure is detected to a value representing the capture target.

4. The traffic monitoring apparatus according to claim 3 , wherein the failure detection circuit is further configured to notify the filter of a start to filter.

5. The traffic monitoring apparatus according to claim 1 further comprising:

a storage configured to store the statistical information file and the capture file; and

an arbitration circuit configured to perform arbitration when holding timings of the statistical information file and the capture file conflict with each other.

6. The traffic monitoring apparatus according to claim 1 , wherein:

the statistical information file includes the first time information supplied by the identical time source, the first time information indicating when aggregation of the plurality of pieces of the statistical information was completed; and

the capture file includes the second time information supplied by the identical time source, the second time information indicating when the packet of the specific flow was filtered.

7. A traffic monitoring method in a traffic monitoring apparatus that monitors traffic of a monitoring target network, the traffic monitoring method comprising:

aggregating, by a statistical information processor of the traffic monitoring apparatus, a plurality of pieces of statistical information to generate a statistical information file based on the plurality of pieces of statistical information, wherein the traffic monitoring apparatus includes a statistical information processor configured to acquire the statistical information per the specific flow of the traffic and a packet capture circuit configured to capture the packet of the specific flow, wherein the traffic monitoring apparatus comprises a memory; and

filtering, by the packet capture circuit of the traffic monitoring apparatus, the packet of the specific flow and generating a capture file based on the filtered packet, wherein the statistical information file is generated in the aggregating in accordance with first time information, the capture file is generated in the filtering in accordance with second time information, the first time information and the second time information are each supplied by an identical time source, and the statistical information processor, the packet capture circuit, and the identical time source are collectively disposed within a single device.

8. The traffic monitoring method according to claim 7 , wherein the statistical information processor includes a rule table configured to record rules corresponding to the specific flow and a capture flag value indicating whether the specific flow is a capture target for each of the rules, and wherein the method further includes:

identifying the specific flow by comparing a rule of the rules recorded in the rule table with a header of an input packet.

9. The traffic monitoring method according to claim 8 , wherein the method further includes:

detecting a failure in the specific flow based on the plurality of pieces of the statistical information; and

updating the capture flag value in the rule table of the specific flow where failure is detected to a value representing the capture target.

10. The traffic monitoring method according to claim 8 further comprising:

storing the statistical information file and the capture file; and

performing arbitration when holding timings of the statistical information file and the capture file conflict with each other.

11. The traffic monitoring method according to claim 7 , wherein:

the statistical information file includes the first time information supplied by the identical time source, the first time information indicating when aggregation of the plurality of pieces of the statistical information was completed; and

the capture file includes the second time information supplied by the identical time source, the second time information indicating when the packet of the specific flow was filtered.

12. A non-transitory computer-readable storage device storing a traffic monitoring program that when executed by one or more processors, cause the one or more processors to execute steps of:

acquiring statistical information per specific flow of traffic;

capturing a packet of the specific flow;

aggregating a plurality of pieces of the statistical information to generate a statistical information file based on the plurality of pieces of the statistical information; and

filtering the packet of the specific flow and generating a capture file based on the filtered packet, wherein the statistical information file is generated in the aggregating in accordance with first time information, the capture file is generated in the filtering in accordance with second time information, the first time information and the second time information are each supplied by an identical time source, and the one or more processors and the identical time source are each disposed within a single device.

13. The computer-readable storage device according to claim 12 , wherein the traffic monitoring program further causes the one or more processors to execute steps of:

identifying the specific flow by comparing a rule recorded in a rule table with a header of an input packet, wherein the rule table records rules corresponding to the specific flow and a capture flag value indicating whether the specific flow is a capture target for each of the rules.

14. The computer-readable storage device according to claim 13 , wherein the traffic monitoring program further causes the one or more processors to execute steps of:

detecting a failure in the specific flow based on the plurality of pieces of the statistical information; and

updating the capture flag value in the rule table of the specific flow where failure is detected to a value representing the capture target.

15. The computer-readable storage device according to claim 12 , wherein the traffic monitoring program further causes the one or more processors to execute steps of:

storing the statistical information file and the capture file; and

performing arbitration when holding timings of the statistical information file and the capture file conflict with each other.

16. The computer-readable storage device according to claim 12 , wherein:

the statistical information file includes the first time information supplied by the identical time source, the first time information indicating when aggregation of the plurality of pieces of the statistical information was completed; and

the capture file includes the second time information supplied by the identical time source, the second time information indicating when the packet of the specific flow was filtered.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2022
From: UZAWA, HIROYUKI; YOSHIDA, SHUHEI; IKEDA, NAMIKO; NITTA, KOYO
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 061762/0323 →
Continuity (1)
Related Publication 20230188439A1 · Jun 15, 2023
Cited By (1)
US 12,568,034