Program network flow monitoring method and system based on Linux operation system
The invention relates to a process network monitoring technology of a domestic Linux operation system, in particular to a related function combining process information and network knowledge. The invention provides a process network monitoring method based on a Linux kernel proc file system, a QWT p...
Gespeichert in:
Hauptverfasser: | , , , |
---|---|
Format: | Patent |
Sprache: | chi ; eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | The invention relates to a process network monitoring technology of a domestic Linux operation system, in particular to a related function combining process information and network knowledge. The invention provides a process network monitoring method based on a Linux kernel proc file system, a QWT plug-in in Qt, pcap packet capture and other mechanisms. The method comprises the following three threads: a first thread is Portmap; a second thread is Sniffer; and a third thread is Maintain. The process network flow monitoring technology designed by the invention has the following characteristics:network flow monitoring of an upper layer and a lower layer is provided, the upper layer maps the whole network card flow and a process port, and the lower layer analyzes the network flow of a process by capturing packets in a link layer. The process control is divided into three stages, namely, the network connection is not limited, the network activity is forbidden, the process is killed and the like. The process is di |
---|