期刊文献+

基于Winpcap的校园网协议统计方法

A campus statistical method based on Winpcap
下载PDF
导出
摘要 针对蠕虫、DDOS攻击的大量存在严重地影响了网络的正常使用情况,使用基于Winpcap的流量监测技术,参照RTFM组织的流(Flow)定义方法,开发了一个简单实用的协议统计系统。系统采用校园网地址后12位作为哈希表的键值并建立一个专门统计传输层TCP、UDP端口以及网络层ICMP协议使用情况的数组。根据系统统计结果,网络管理者就可以判断校园网络是否处于正常运行状态,把网络管理者从传统的经验管理模式中解放出来,提高了网络管理与维护的效率。 The Worms and DDOS attacks have seriously affected the Intemet. So a simple and practical protocol statistical system was developed based on Winpcap traffic monitoring scheme and the RTFM' s definition of flow. The last 12 bits of campus network address was chosed as a hash table key and built a counter struct array on recording the TCP, UDP ports and ICMP usage. According to the statistical results, the network administrators can estimate if the campus network is in normal running state, which liberate the net- work administrators from traditional experienced mode of network management and improve the efficiency of network management.
出处 《鞍山科技大学学报》 2006年第3期259-262,共4页 Journal of Anshan University of Science and Technology
关键词 WINPCAP 哈希表 网络管理 流量监测 Winpcap flow hashtable Network management traffic monitoring
  • 相关文献

参考文献7

  • 1PAXSON V, MAHDAVI J, ADAMS A, et al. An architecture for large-scale Internet measurement[J ]. IEEE Communications, 1998,36(8) :48 - 54. 被引量:1
  • 2CFIEN Thomas M, HU Lucia. Internet performance monitoring[ DI3/OL]. http://engr.smu. edu/tchen/papers/ProcIEEE- Aug2002. pdf 被引量:1
  • 3PAXSON Vern. Toward a framework for defining Internet performance metrics[DB/OL]. http://www.isoc. org/inet96/proceedings/d3/d3.3. htm 被引量:1
  • 4OETIKER Tobi. The multi router traffic grapher[DB/OL].http://oss.oetiker. ch/mrtg/index.en.html 被引量:1
  • 5Whitepaper: Introduction to Cisco IOS NetFlow-A technical overview [ DB/OL]. http ://www. cisco.com/en/US/products/ ps6601/products.white.paper0900aecd80406232.shtml 被引量:1
  • 6BROWNLEE N, MILLS C, RUTH G. RFC 2722: traffic flow measurement- architecture[DB/OL]. http://www. faqs. org/rfcs/rfc2722.html 被引量:1
  • 7HAN Se-hee, KIM Myung-sup,JU Hong-taek, et al. The architecture of NG-MON: a passive network monitoring system for high-speed IP networks[DB/OL]. http://dpnm.postech.ac. kr/papers/DSOM/02/ngmon/ngmon- dsom2002.pdf 被引量:1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部