IP Library Granted Patent US 12,381,801
Granted Patent B2
US 12,381,801 · App. 18/573,730 · Granted Aug 5, 2025

Traffic monitoring device and traffic monitoring method

Inventors: Hiroyuki Uzawa (Tokyo, JP); Yusuke Sekihara (Tokyo, JP); Saki Hatta (Tokyo, JP); Shuhei Yoshida (Tokyo, JP); Namiko Ikeda (Tokyo, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
H04L43/0876H04L43/026H04L43/022
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,801
App. No.
18/573,730
Granted
Aug 5, 2025
Kind
B2
Abstract

A traffic monitoring device includes an identification unit that identifies a flow of a packet received from a monitoring target network into a flow of a first flow group and a second flow group other than the first flow group on the basis of a rule table in which a predetermined rule is registered, a traffic aggregation unit that aggregates a traffic amount of the first flow group for each flow, an occurrence probability calculation unit that calculates an occurrence probability of each flow on the basis of a result of sampling at least some of the flow of the packet received, and a traffic estimation unit that estimates a traffic amount of each flow of the second flow group by multiplying the occurrence probability of each flow by the total value of the traffic amount of the second flow group.

Claims (54)

1. A traffic monitoring device, the device comprising:

one or more processors; and

a storage device storing a program to be executed by the one or more processors, the program including instructions for:

identifying a flow of each packet of a plurality of packets received from a monitoring target network as a first flow of a first flow group or a second flow of a second flow group different from the first flow group based on a rule table in which a predetermined rule is registered;

aggregating a traffic amount of each of the first flows of the first flow group;

calculating an occurrence probability of each flow based on a result of sampling the flows of the plurality of packets; and

estimating the traffic amount of each of the second flows of the second flow group by multiplying a total value of the traffic amount of the second flow group by the occurrence probability of each of the second flows of the second flow group.

2. The device according to claim 1 , wherein the program further includes instructions for:

capturing the packet of the flow that has flowed into a sampling section at a predetermined interval;

calculating the occurrence probability of the flow in the sampling section from the packet that has been captured; and

calculating the occurrence probability of each flow by averaging and normalizing pieces of the occurrence probability in a plurality of the sampling sections.

3. The device according to claim 2 , wherein the program further includes instructions for:

calculating an estimated value of the traffic amount of each of the first flows of the first flow group by multiplying the traffic amount of the flow of the packet that has been received by the occurrence probability of each flow; and

estimating a maximum value and a minimum value of the traffic amount of each of the second flows of the second flow group by using a difference between the aggregated traffic amount of each of the first flows of the first flow group and the estimated value of the traffic amount of each of the first flows of the first flow group.

4. The device according to claim 3 , wherein the rule of the rule table is determined based on the aggregated traffic amount of each of the first flows of the first flow group and the estimated value of the traffic amount of each of the second flows of the second flow group.

5. The device according to claim 2 , wherein the rule of the rule table is determined based on the aggregated traffic amount of each of the first flows of the first flow group and the estimated value of the traffic amount of each of the second flows of the second flow group.

6. The device according to claim 1 , wherein the program further includes instructions for:

calculating an estimated value of the traffic amount of each of the first flows of the first flow group by multiplying the traffic amount of the flow of the packet that has been received by the occurrence probability of each flow; and

estimating a maximum value and a minimum value of the traffic amount of each of the second flows of the second flow group by using a difference between the aggregated traffic amount of each of the first flows of the first flow group and the estimated value of the traffic amount of each of the first flows of the first flow group.

7. The device according to claim 1 , wherein the rule of the rule table is determined based on the aggregated traffic amount of each of the first flows of the first flow group and the estimated value of the traffic amount of each of the second flows of the second flow group.

8. A traffic monitoring method in a traffic monitoring device that monitors traffic of a plurality of packets flowing through a monitoring target network, the method comprising:

identifying a flow of each packet of the plurality of packets received from the monitoring target network into a first flow of a first flow group or a second flow of a second flow group different from the first flow group based on a rule table in which a predetermined rule is registered;

aggregating a traffic amount of each of the first flows of the first flow group;

calculating an occurrence probability of each flow based on a result of sampling the flows of the plurality of packets; and

estimating the traffic amount of each of the second flows of the second flow group by multiplying a total value of the traffic amount of the second flow group by the occurrence probability of each of the second flows of the second flow group.

9. The method according to claim 8 , wherein calculating the occurrence probability of each flow further comprises:

capturing the packet of the flow that has flowed into a sampling section at a predetermined interval;

calculating the occurrence probability of the flow in the sampling section from the packet that has been captured; and

calculating the occurrence probability of each flow by averaging and normalizing pieces of the occurrence probability in a plurality of the sampling sections.

10. The method according to claim 9 , wherein estimating the traffic amount further comprises:

calculating an estimated value of the traffic amount of each of the first flows of the first flow group by multiplying the occurrence probability of each flow by the traffic amount of the flow of the packet that has been received; and

estimating a maximum value and a minimum value of the traffic amount of each of the second flows of the second flow group by using a difference between the aggregated traffic amount of each of the first flows of the first flow group and the estimated value of the traffic amount of each of the first flows of the first flow group.

11. The method according to claim 10 , wherein the rule of the rule table is determined based on the aggregated traffic amount of each of the first flows of the first flow group and the estimated value of the traffic amount of each of the second flows of the second flow group.

12. The method according to claim 9 , wherein the rule of the rule table is determined based on the aggregated traffic amount of each of the first flows of the first flow group and the estimated value of the traffic amount of each of the second flows of the second flow group.

13. The method according to claim 8 , wherein estimating the traffic amount further comprises:

calculating an estimated value of the traffic amount of each of the first flows of the first flow group by multiplying the occurrence probability of each flow by the traffic amount of the flow of the packet that has been received; and

estimating a maximum value and a minimum value of the traffic amount of each of the second flows of the second flow group by using a difference between the aggregated traffic amount of each of the first flows of the first flow group and the estimated value of the traffic amount of each of the first flows of the first flow group.

14. The method according to claim 8 , wherein the rule of the rule table is determined based on the aggregated traffic amount of each of the first flows of the first flow group and the estimated value of the traffic amount of each of the second flows of the second flow group.

15. A traffic monitoring method in a traffic monitoring device that monitors traffic of a plurality of packets flowing through a monitoring target network, the method comprising:

identifying a flow of each packet of the plurality of packets received from the monitoring target network into a registered flow or an unregistered flow based on a rule table in which a predetermined rule is registered;

for each of the registered flows, aggregating a traffic amount of each of the registered flows;

for each of the unregistered flows, aggregating the traffic amount of each of the unregistered flows and calculating a total value of the traffic amounts of the unregistered flows;

calculating an occurrence probability of each of the unregistered flows based on a result of sampling the flows of the plurality of packets; and

estimating the traffic amount of each of the unregistered flows by multiplying the total value of the traffic amounts of the unregistered flows by the occurrence probability of each of the unregistered flows.

16. The method according to claim 15 , wherein estimating the traffic amount of each of the unregistered flows comprises:

obtaining the total value of the traffic amounts of the unregistered flows;

acquiring the occurrence probability of each of the unregistered flows;

multiplying the total value of the traffic amounts of the unregistered flows by the occurrence probability of each of the unregistered flows; and

outputting the multiplied result as an estimated value of the traffic amount of each of the unregistered flows.

17. The method according to claim 15 , wherein sampling the flows of the plurality of packets comprises:

identifying the flow of each of the packets sampled within a sampling section;

calculating the occurrence probability of each of the unregistered flows within the sampling section; and

generating a traffic distribution in the sampling section.

18. The method according to claim 17 , wherein sampling the flows of the plurality of packets further comprises performing averaging and normalization processing by using a plurality of the traffic distributions generated for a plurality of the sampling sections to calculate the occurrence probability of each of the unregistered flows.

Assignments (2)
CHANGE OF NAME Recorded Aug 27, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072596/0266 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2023
From: UZAWA, HIROYUKI; SEKIHARA, YUSUKE; HATTA, SAKI; YOSHIDA, SHUHEI; IKEDA, NAMIKO
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 065944/0584 →
Continuity (1)
Related Publication 20240235974A1 · Jul 11, 2024
References Cited (10)
US 11683255B2 · Yoshida · 2023 [cited by examiner]
US 20220417118A1 · Ukon et al. · 2022 [cited by applicant]
US 20230067780A1 · Shimoda · 2023 [cited by examiner]
US 20240372815A1 · Sirov · 2024 [cited by examiner]
US 20240406089A1 · Hatta · 2024 [cited by examiner]
JP 201223687 · 2012 [cited by examiner]
WO WO2020230265A1 · 2020 [cited by examiner]
WO 2021001879A1 · 2021 [cited by applicant]
Ikeda et al., “Traffic Monitoring System for Network Virtualization with Hardware Accelerator (1) ˜ System Architecture to Realize Traffic Visualization ˜,” 2020 General Meeting of the Institute of Electronics, Informat… [cited by applicant]
Kawahara et al., “Abnormal traffic measurement analysis method,” NTT Technical Journal. vol. 20, No. 3, 2008, 5 pages. As discussed in the specification. [cited by applicant]