The traffic monitoring approaches such as snmp , netflow have limitations ; while special devices such as smartbit are expensive Snmp 、 netflow等流量監(jiān)測(cè)方式存在很大局限性;而專用的流量監(jiān)測(cè)設(shè)備如smartbit等則價(jià)格昂貴。
This paper introduce and compare snmp agreement and cisco netflow technology on the network flux monitoring technology , and have realized the analysis and handling the data flow of wide area network using netflow technology 在網(wǎng)絡(luò)流量監(jiān)控技術(shù)上,本文介紹和對(duì)比了snmp協(xié)議和cisconetflow技術(shù),并利用netflow技術(shù)實(shí)現(xiàn)了廣域網(wǎng)數(shù)據(jù)流量的分析和處理。
There are many techniques based on netflow to analyse the traffic flow and provide accounting and billing information of the network service . it has been applied to monitor behavior of network user and traffic flow and usage of network services 目前netflow技術(shù)用于對(duì)ip網(wǎng)絡(luò)通信流量進(jìn)行分析和計(jì)量,為網(wǎng)絡(luò)的運(yùn)行提供準(zhǔn)確的統(tǒng)計(jì)數(shù)據(jù),在園區(qū)網(wǎng)用戶行為監(jiān)控、流量監(jiān)控、網(wǎng)絡(luò)服務(wù)使用狀況監(jiān)控等方面有很成熟的應(yīng)用。
Netflow is a technology which is used to accelerate data switch in network equipment by cisco system . it has a powerful data collection and analysis capability and is becoming the uppermost criterion for ip / mpls traffic flow . which is applied widely in network management field Netflow技術(shù)是思科公司用在網(wǎng)絡(luò)設(shè)備上進(jìn)行數(shù)據(jù)加速交換的一項(xiàng)技術(shù),它的數(shù)據(jù)采集和測(cè)量功能成為最主要的ip / mpls流量分析和計(jì)量標(biāo)準(zhǔn),廣泛應(yīng)用于網(wǎng)絡(luò)管理領(lǐng)域。
In the first part of the article , i enumerated several solutions to email filter , and analyzied their advantage " and disadvantage . then email ' s characteristic has been presented in the paper . at last , i main introduced the copied netflow and the filtered netflow 文章第一部分主要是介紹了郵件過濾方面,幾種主要的解決方案,并且分析了每種解決方案的優(yōu)點(diǎn)和缺點(diǎn)。然后從郵件的基本特點(diǎn)出發(fā),介紹了郵件傳輸過程、延遲交付、文電格式等相關(guān)的技術(shù)。
The test shows that the method has the positive results on determining the anomaly traffic and on the threats assessment process . this method can distinguish the abnormal traffic , which is harmful for the bandwith , from the netflow sample and gives a reference value of its threat level and never need analyzing the content of the packets 實(shí)驗(yàn)和分析表明本文提出的威脅評(píng)估方法對(duì)網(wǎng)絡(luò)中的異常流量確定和威脅的定量分析是有效的,并不需要對(duì)netflow數(shù)據(jù)數(shù)據(jù)包內(nèi)容的進(jìn)行分析,就可以確定對(duì)網(wǎng)絡(luò)可用性影響較大的異常網(wǎng)絡(luò)流,并給出其威脅度的量化指標(biāo)。
The article is about billing of ip network , especially on the aspects of theory and structure . it has researched the reality of ip billing , include three tiers web structure , cmm of sei , oob technology , radius protocol , netflow and the technology of integration 本文深入研究了網(wǎng)絡(luò)計(jì)費(fèi)技術(shù)的原理和體系結(jié)構(gòu),探索了網(wǎng)絡(luò)計(jì)費(fèi)系統(tǒng)的實(shí)現(xiàn)技術(shù),包括基于web的信息系統(tǒng)三層體系結(jié)構(gòu)、軟件開發(fā)標(biāo)準(zhǔn)? cmm 、面向?qū)ο蠹夹g(shù)、 radius認(rèn)證記費(fèi)技術(shù)、網(wǎng)絡(luò)數(shù)據(jù)流量采集與整合技術(shù)等。
In this paper , by studying the feature of the netflow data and the mib status of the network equipments , at the same time , in terms of analyzing the characteristics of network attack , worm spread , virus infection and network misuse behaviors , our work is based on the facts that most of the anomaly traffic in campus network has influences of the netflow data and network equipment status . an approach is present to assess the threats of the traffic in terms of five factors : the traffic bytes distribution , flow number distribution , packets number distribution , equipment cpu utilization and the memory utilization . the weight of each factor is computed and determined by fuzzy relation matrix 。 an prototype system is designed to test the method and the results are analyzed to evaluate the availability of our method 本文研究了netflow流數(shù)據(jù)的特征和網(wǎng)絡(luò)設(shè)備運(yùn)行狀態(tài)數(shù)據(jù),分析了校園網(wǎng)網(wǎng)絡(luò)異常攻擊、蠕蟲病毒和網(wǎng)絡(luò)濫用行為的特點(diǎn),基于大多數(shù)的網(wǎng)絡(luò)流異常必然反映在網(wǎng)絡(luò)網(wǎng)絡(luò)流量數(shù)據(jù)特征的變化以及網(wǎng)絡(luò)設(shè)備運(yùn)行狀態(tài)的改變這樣一個(gè)事實(shí),提出了一套基于網(wǎng)絡(luò)流量和網(wǎng)絡(luò)設(shè)備運(yùn)行狀態(tài)的異常威脅評(píng)估方法,確定了5種威脅評(píng)估因素:網(wǎng)絡(luò)流帶寬分布、網(wǎng)絡(luò)流數(shù)量分布、網(wǎng)絡(luò)流包數(shù)量分布、網(wǎng)絡(luò)設(shè)備cpu利用率、網(wǎng)絡(luò)設(shè)備內(nèi)存利用率,并采用模糊關(guān)系矩陣方法計(jì)算和分配這5種評(píng)估因素在評(píng)估函數(shù)中的權(quán)重。
百科解釋
NetFlow is a network protocol developed by Cisco Systems for collecting IP traffic information. NetFlow has become an industry standard for traffic monitoring and is supported on various platforms, see NetFlow support below.