KR20150033816A - Device for Detecting Abnormal Surge in Control Packet - Google Patents
Device for Detecting Abnormal Surge in Control Packet Download PDFInfo
- Publication number
- KR20150033816A KR20150033816A KR20130113408A KR20130113408A KR20150033816A KR 20150033816 A KR20150033816 A KR 20150033816A KR 20130113408 A KR20130113408 A KR 20130113408A KR 20130113408 A KR20130113408 A KR 20130113408A KR 20150033816 A KR20150033816 A KR 20150033816A
- Authority
- KR
- South Korea
- Prior art keywords
- control packet
- abnormal increase
- unit
- control
- detection device
- Prior art date
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/04—Processing captured monitoring data, e.g. for logfile generation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/16—Threshold monitoring
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L47/00—Traffic control in data switching networks
- H04L47/10—Flow control; Congestion control
- H04L47/12—Avoiding congestion; Recovering from congestion
- H04L47/125—Avoiding congestion; Recovering from congestion by balancing the load, e.g. traffic engineering
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Mining & Analysis (AREA)
- Mobile Radio Communication Systems (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
The present invention relates to a control packet abnormality increase detecting apparatus, comprising: a collecting unit for collecting or capturing a plurality of packets transmitted and received between a plurality of wireless terminal apparatuses and a plurality of servers through a communication network; A measurement unit for measuring an amount of occurrence of a control packet generated for each IP in the last n seconds for each of the flags after classification; and a measurement unit for measuring the number of control packet flags generated in the past time period based on the current time, A recording unit for performing recording for a predetermined period of time and calculating an average or maximum generation amount using information on the number of flags recorded in units of seconds for a predetermined period of time; Detect abnormal increase of control packet by using mean value or maximum value of inflow per second It is provided with parts determined.
Description
The present invention is intended to detect an abnormal increase in a control packet, which is a main cause of a wireless network load.
Since the spread of smartphones, the usage patterns of individual users are rapidly changing from voice calls to data communication.
As shown in the mobile (wireless) data traffic indicator in Figure 1, mobile traffic is expected to increase by about 26 times over the next 10 to 15 years. In 2010, the amount of mobile data used by individuals in a day was 15 MB, It can be up to 1GB.
This increase in mobile traffic directly affects the profitability and service quality of mobile carriers, and it is inevitable that profitability deterioration is accompanied by equipment expansion of service providers, such as mobile carriers, In addition, service dissatisfaction increases due to a delay in data communication speed.
As a result, mobile telecommunication carriers have been struggling to utilize the network infrastructure effectively to reduce the investment burden and ensure the quality of service.
Meanwhile, as shown in FIG. 2, a main factor of mobile network congestion is traffic channel generation with a server on a communication network through various applications installed in a wireless terminal device.
That is, in order to generate a single traffic channel with a server on a communication network, a wireless terminal apparatus must precede several tens of times of signal communication with apparatuses on a communication network such as a position determination of a base station. Causing a larger load.
Also, in a situation where a plurality of wireless terminal devices are connected to a server by using a TCP protocol in one server (divided into IP), the server is shut down normally for server management or the server is down due to various reasons, A control packet in which a control flag of RST or FIN, which is a control flag of TCP, is transmitted to the wireless terminal devices connected to the server in a short period of time.
In a situation where a server of a large number of users is connected to a plurality of wireless terminal devices, a control packet may instantaneously show an explosive increase state. In particular, in a wireless network, So that an overload can be generated.
In conclusion, in order to solve the problem of dissatisfaction of service users of wireless terminals and the enormous cost of mobile communication service providers due to network congestion, it is necessary to increase the number of control packets due to server information and traffic channel generation / However, there is no way to handle such monitoring more easily and conveniently on a communication network system.
The recognition of the problems and problems of the prior art is not obvious to a person having ordinary skill in the art, so that the inventive step of the present invention should not be judged based on the recognition based on such recognition I will reveal.
An object of the present invention to solve the above problems is to classify a plurality of packets transmitted and received between a plurality of wireless terminal devices and a plurality of servers through a communication network by each server IP and detect an abnormal increase of control packets generated for each IP Which is one of the causes of the overload of the mobile network.
It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory and are not restrictive of the invention, as claimed, but are not to be construed as limiting the invention. There will be.
The control packet abnormal increase detecting apparatus according to the present invention includes a collecting unit for collecting or capturing a plurality of packets for mutually transmitting and receiving a plurality of wireless terminal apparatuses and a plurality of servers through a communication network; A measurement unit for measuring an amount of generation of control packets generated for each IP in the last n seconds for each of the flags, a measurement unit for counting the number of control packet flags generated over a certain period of time based on the current time, And a control unit for controlling the amount of generation of control flags per second measured by the measuring unit and the number of flags calculated per second by the flag calculated by the recording unit, A version that detects an abnormal increase in control packets using the average or maximum value of inflow And a unit.
According to another aspect of the present invention, the control packet abnormality detection apparatus may further include a communication unit for notifying at least one terminal or server of an increase in control packet abnormality when an abnormal increase in the control packet is detected as a result of the determination unit .
According to another aspect of the present invention, the determination unit determines that an abnormal increase in the control packet occurs when the amount of occurrence per second of the specific flag exceeds a preset upper limit value, or if the amount of occurrence per second per flag is greater than the average value of the inflow amount per second If the number of control packets increases by more than a multiple and exceeds a predetermined lower limit value, it can be determined that the control packet is abnormally increased.
According to another aspect of the present invention, the determination unit may determine that the IP information of the server in which the abnormal increase has occurred, the abnormal increase occurrence time information, and the information on the control packets from the predetermined fixed time to the predetermined time after the abnormal increase occurring time, And the number of control packet flags generated during the predetermined time period based on the current time in the recording unit can be adjusted for recording for a certain period of time in units of seconds and for a certain period of time.
According to an aspect of the present invention, it is possible to more easily and quickly perform monitoring, which can control a network overload due to abnormal increase of control packets with a specific server, by detecting abnormal increase of control packets on a communication network between a wireless terminal device and a server It has the effect of being able to.
Another effect according to an aspect of the present invention is to control connection to a specific server that leads to an excessive control packet increase phenomenon, thereby optimizing the use of the network, Can be minimized.
Another effect of the present invention is to minimize dissatisfaction of a user of a wireless terminal device due to delay in data communication or the like, and to reduce battery consumption of a wireless terminal device by optimizing network utilization.
BRIEF DESCRIPTION OF THE DRAWINGS The accompanying drawings, which are incorporated in and form a part of the specification, illustrate preferred embodiments of the invention and, together with the description of the invention given above, serve to further the understanding of the technical idea of the invention. And should not be construed as interpretation.
1 is a diagram illustrating a mobile (wireless) data traffic indicator.
2 is a diagram showing one of the main factors of conventional mobile network congestion.
3 is a block diagram illustrating a configuration of a control packet abnormal increase detection apparatus according to an embodiment of the present invention.
4 is a diagram showing an example of a packet including a general control packet.
FIG. 5 is a diagram illustrating an embodiment of the measured control packet.
FIG. 6 is a diagram showing another embodiment of the measured control packet.
Figure 7 is an embodiment of measuring the amount of generation per second of control flags according to an embodiment of the present invention.
8 is a diagram illustrating a process for detecting an abnormal increase in a control packet according to an embodiment of the present invention.
The operation principle of the preferred embodiment of the present invention will be described in detail with reference to the accompanying drawings and description. It should be understood, however, that the drawings and the following detailed description are exemplary and explanatory and are intended to provide further explanation of the invention, and are not to be construed as limiting the present invention. In the following description of the present invention, a detailed description of known functions and configurations incorporated herein will be omitted when it may make the subject matter of the present invention rather unclear. The terms used below are defined in consideration of the functions of the present invention, which may vary depending on the user, intention or custom of the operator. Therefore, the definition should be based on the contents throughout the present invention.
As a result, the technical idea of the present invention is determined by the claims, and the following embodiments are merely means for effectively explaining the technical idea of the present invention to a person having ordinary skill in the art to which the present invention belongs Only.
FIG. 3 is a diagram showing a main configuration of a control packet abnormal
3 shows a control packet
Each of the configurations shown in FIG. 3 is a configuration for explaining an embodiment of the present invention, and the technical features of the present invention are not limited only by the implementation method shown in FIG.
According to an embodiment of the present invention, the control packet abnormal
Here, the control packet may be generated when a
Further, the abnormal increase means that the amount of generation per second of the control packet exceeds a predetermined criterion, and it is preferable that the n second is 1 second.
3, a control packet abnormal
Here, the control packet abnormality increase detecting
Referring to FIG. 3, the
According to an embodiment of the present invention, when the
Generally, in order to perform session connection (SYN), data transmission / reception, session termination (FIN), and session restart (RST) between the
4 shows an example of header information of a packet transmitted and received between the
4, among the header information, " RST (1 bit)? Reset the connection "," SYN (1 bit)? Synchronize sequence numbers. Only the first packet sent from each end should have this flag set. Some other flag s change meaning based on this flag, and some -are only valid for when it is set, and others when it is clear "," FIN (1 bit)? No more data from sender ".
The present invention detects a case where the amount of control flag is increased excessively such as when a control packet in which a large amount of FIN or RST is set in a short time from the
The measuring
5 illustrates an example in which the number of control flags transmitted / received by the
Referring to FIG. 5, it can be seen that a certain amount of FIN, SYN, and RST packets are generated from the
FIG. 6 is a graph showing a graph for detecting abnormal increase related information based on a time point at which abnormal increase of a control packet is confirmed as shown in FIG.
According to an embodiment of the present invention, the control packet abnormal
FIG. 7 is a flowchart illustrating a process of classifying packets currently flowing through the measuring
Here, TX denotes a packet sent from the
According to an embodiment of the present invention, the time at which a packet is captured is recorded in units of milliseconds (1/1000 second) in a packet captured and received from the collecting
The
The judging
According to the present invention, the determination unit (40) determines that an abnormal increase in the control packet occurs when the amount of occurrence per second of the specific flag exceeds a predetermined upper limit value, or if the amount of occurrence per second per flag is larger than the average value It is judged that the control packet is abnormally increased if it exceeds the predetermined lower limit value.
In addition, the
The output unit 50 according to an embodiment of the present invention outputs an alarm when an abnormal increase of the control packet is detected as a result of the
According to the present invention, the output unit 50 may output an alarm on a monitoring screen or an alarm through a speaker.
The
According to the present invention, the
According to the present invention, each component of the control packet abnormal
8 is a diagram illustrating a process for detecting an abnormal increase in a control packet according to an embodiment of the present invention.
First, the control packet abnormal
Thereafter, the control packet abnormality
Thereafter, the measuring
In step S840, the abnormal
Thereafter, the abnormal
Here, steps S820 and S830 may be performed in step S840, step S850, and steps S820 and S830, step S840, and step S850. May be performed at the same time.
Thereafter, the packet abnormal
If it is determined in step S860 that the amount of occurrence of the specific flag per second exceeds the predetermined upper limit value in step S870, the
If it is determined in step S860 that the amount of occurrence of the specific flag per second does not exceed the predetermined upper limit value in step S880, the packet abnormal
If it is determined in step S885 that the amount of occurrence per second per flag is greater than a predetermined multiple of the average value of the inflow per second per flag and exceeds the set lower limit value in step S890, The
If it is determined in step S885 that the amount per second generated per flag does not increase by more than a predetermined number of times larger than the average value of the inflow amount per second per flag or does not exceed a predetermined lower limit value or becomes larger than a predetermined multiple, If the set lower limit value is not exceeded (S895), the control packet abnormality
In FIG. 8, steps S860 and S885 are sequentially performed for explaining an embodiment of the present invention. However, steps S860 and S885 may be performed in sequence, It is acceptable.
Although not shown in the drawing, when abnormal increase of the control packet is detected in step S875, the control packet abnormal
100: control packet abnormal increase detection device
200: wireless terminal device 300: server
10: collecting section 20: measuring section
30: recording unit 40:
50: output unit 60: communication unit
Claims (10)
A measuring unit for classifying the packets collected or captured by the collecting unit according to the server IP and measuring the amount of the control packet generated for each IP for the last n seconds for each flag;
A recording unit for recording the number of control packet flags generated for a predetermined period of time based on the current time for a predetermined time in units of seconds and calculating an average or maximum generation amount using the number of flags recorded in units of seconds for a predetermined period of time; ;
And a determination unit for detecting an abnormal increase in a control packet by using an average value or a maximum value of an inflow amount per second for each flag calculated in the recording unit and a generation amount per second of control flags measured by the measurement unit,
Control packet abnormal increase detection device.
Further comprising an output unit for outputting an alarm when a result of detection by the determination unit indicates that an abnormally increased control packet has been detected,
Control packet abnormal increase detection device.
Further comprising a communication unit for notifying at least one terminal or server of an increase in control packet abnormality when an abnormal increase in the control packet is detected as a result of the determination by the determination unit,
Control packet abnormal increase detection device.
When the amount of occurrence per second of the specific flag exceeds the predetermined upper limit value, it is determined that the control packet is abnormal increase, or
When the amount of generated per second per flag is larger than the average value of the inflow amount per second per flag and exceeds the predetermined lower limit value,
Control packet abnormal increase detection device.
Detecting one or more pieces of information on control packets from a predetermined time to a predetermined time after the abnormal increase occurrence time,
Control packet abnormal increase detection device.
A control unit for controlling the number of control packet flags generated for a predetermined time based on the current time in the recording unit,
Control packet abnormal increase detection device.
When the server is shut down due to one or more causes and the connection with the wireless terminal device is cut off, the TCP connection to the wireless terminal devices connected to the server is terminated (RST), a session end (FIN), or a session connection (SYN) is set as a control flag.
Control packet abnormal increase detection device.
(RST), end of session (FIN), connection of session (SYN)
Control packet abnormal increase detection device.
And the generation amount per second of the control packet exceeds a preset arbitrary criterion.
Control packet abnormal increase detection device.
1 < / RTI >
Control packet abnormal increase detection device.
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR20130113408A KR20150033816A (en) | 2013-09-24 | 2013-09-24 | Device for Detecting Abnormal Surge in Control Packet |
PCT/KR2014/003397 WO2015046697A1 (en) | 2013-09-24 | 2014-04-18 | Apparatus for detecting abnormal increase of control packets, method therefor, and recording medium |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR20130113408A KR20150033816A (en) | 2013-09-24 | 2013-09-24 | Device for Detecting Abnormal Surge in Control Packet |
Publications (1)
Publication Number | Publication Date |
---|---|
KR20150033816A true KR20150033816A (en) | 2015-04-02 |
Family
ID=53030916
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
KR20130113408A KR20150033816A (en) | 2013-09-24 | 2013-09-24 | Device for Detecting Abnormal Surge in Control Packet |
Country Status (1)
Country | Link |
---|---|
KR (1) | KR20150033816A (en) |
-
2013
- 2013-09-24 KR KR20130113408A patent/KR20150033816A/en not_active Application Discontinuation
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN106850337B (en) | Network quality detection method and device | |
US9030959B2 (en) | Apparatus and method for monitoring quality metrics associated with a wireless network | |
US20070165535A1 (en) | Method, device and system for monitoring network performance | |
US9462486B2 (en) | Method and device for classifying wireless data service | |
EP1972073A2 (en) | Wlan diagnostics using traffic stream metrics | |
EP2621135B1 (en) | A method and a system for providing a flexible secondary data path | |
EP2741439B1 (en) | Network failure detecting method and monitoring center | |
US10756987B2 (en) | Technique for handling service level related performance data for roaming user terminals | |
Alvarez et al. | Field measurements of mobile services with Android smartphones | |
US8976689B2 (en) | Methods, systems, and computer program products for monitoring network performance | |
US20150085651A1 (en) | Analysis server and mobile network system | |
KR101514633B1 (en) | Method and apparatus for managing speech quality in packet network | |
JP2014107825A (en) | Communication path identification device | |
CN107889126B (en) | Network state identification method, DPI monitoring and analyzing equipment and network system | |
CN110972199A (en) | Flow congestion monitoring method and device | |
CN107547444B (en) | Traffic statistical method and switching equipment | |
KR20150033820A (en) | Recording Medium, Method for Detecting Surge in Control Packet Traffic | |
KR20150033816A (en) | Device for Detecting Abnormal Surge in Control Packet | |
KR20150072472A (en) | Device for Detecting Abnormal Surge in Control Packet | |
Guo et al. | Network Quality Monitoring for Typical Power Services | |
WO2015091869A1 (en) | Distributed saturation detection method for wireless network nodes | |
US9419866B2 (en) | Method, node, and monitoring center detecting network fault | |
KR20140112646A (en) | Recording Medium, Method and Device for Detection of Signal | |
WO2021241624A1 (en) | Data collection method, sensor device, server device, visualization system, and non-transitory computer-readable medium | |
WO2024224142A1 (en) | Transport reporting by radio for analytics |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
WITN | Withdrawal due to no request for examination |