摘要
实现了一个基于WinPcap的实时网络流量监测系统,完成了数据包级和流级的流量指标,包括2~7层协议分布,不同协议的流量速率,包大小分布,不同聚集程度的流分布。前N名的IP主机和主机对分布等;并提供网络运行状态的告警指标.实验结果表明,对于100M以太网。基于WinPeap的软件捕获流量监测程序的处理上限为60000packet/s,完全可以胜任100M以太网监测需求.
This paper provided a real-time network monitor system based on WinPcap, which supported packet level and flow level traffic metrics such as link utilization, protocol distribution in 2-7 protocol levels, various aggravated flow distribution, top NIP host and IP host pair. The monitor system also supported network worrying and alert statistics. Performance evaluations have shown that the monitor system can process up to 60 000 packets per sec on 100 M Ethernet link. This demonstrates that the software network monitor system is applicable to 100 M Ethernet Networks.
出处
《湖南大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2006年第2期118-121,共4页
Journal of Hunan University:Natural Sciences
基金
国家自然科学基金资助项目(60473031
60273070
60403031)
国家863高技术研究发展计划资助项目(2005AA121560)
关键词
流量分析
被动网络测试
计算机网络
网络协议
network traffic analysis
passive network measurement
computer network
network protocols