-
公开(公告)号:WO2016191486A1
公开(公告)日:2016-12-01
申请号:PCT/US2016/034145
申请日:2016-05-25
Applicant: CISCO SYSTEMS, INC.
Inventor: MCCGREW, David , ZAWADOWSKIY, Andrew , O'HARA, Donovan , RADHAKRISHNAN, Saravanan , PEVNY, Tomas , WING, Daniel G.
IPC: H04L29/06
CPC classification number: H04L63/1408 , H04L63/166 , H04L2463/121
Abstract: A method comprises receiving, at a network infrastructure device, a flow of packets, determining, using the network infrastructure device and for a first subset of the packets, that the first subset corresponds to a first datagram and determining a first length of the first datagram, determining, using the network infrastructure device and for a second subset of the packets, that the second subset corresponds to a second datagram that was received after the first datagram, and determining a second length of the second datagram, determining, using the network infrastructure device, a duration value between a first arrival time of the first datagram and a second arrival time of the second datagram, sending, to a collector device that is separate from the network infrastructure device, the first length, the second length, and the duration value for analysis.
Abstract translation: 一种方法包括在网络基础设施设备处接收分组流,使用网络基础设施设备和分组的第一子集来确定第一子集对应于第一数据报并且确定第一数据报的第一长度 确定使用所述网络基础设施设备和所述分组的第二子集,所述第二子集对应于在所述第一数据报之后接收到的第二数据报,以及确定所述第二数据报的第二长度,使用所述网络基础设施 设备,第一数据报的第一到达时间与第二数据报的第二到达时间之间的持续时间值,向与网络基础设施设备分离的收集器设备发送第一长度,第二长度和持续时间 价值分析。