High-frequency network detection method and device, electronic equipment and readable storage medium

By creating original sockets on the source detection node and constructing multiple detection request packets, the problem of excessive resource occupation in the prior art is solved, and the efficiency and accuracy of high-frequency network detection is achieved.

CN120166047APending Publication Date: 2025-06-17BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510214480.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

When using existing high-frequency network detection technology, the source detection nodes require a large number of network connections, resulting in excessive CPU and memory resource usage, affecting the detection process.

Method used

By creating the original socket, multiple probe request packets are constructed according to the target value, and sending and receiving probe packets through one socket, avoiding the establishment of multiple network connections.

Benefits of technology

Reduce the resource occupation of source detection nodes, improve the packet collection performance and data processing performance, and achieve the purpose of high-frequency network detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120166047A_ABST
    Figure CN120166047A_ABST
Patent Text Reader

Abstract

The invention provides a high-frequency network detection method and device, electronic equipment and a readable storage medium, and relates to the technical field of artificial intelligence such as big data, cloud services, the Internet of Things and cloud computing. The high-frequency network detection method applied to a source detection node comprises the following steps: taking a result of multiplying a target link number between the source detection node and a target detection node by a preset numerical value as a target numerical value; creating an original socket, and constructing a plurality of detection request packets according to the target numerical value; sending the plurality of detection request packets to a target detection node through the original sockets; receiving a detection return packet sent by the target detection node through the original socket; and obtaining the network connection state according to the plurality of detection request packets and the detection return packets. The high-frequency network detection method applied to a target detection node comprises the following steps: receiving a detection request packet sent by a source detection node; and obtaining a detection return packet according to the detection request packet, and sending the detection return packet to the source detection node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and particularly to artificial intelligence technologies such as big data, cloud services, Internet of Things, and cloud computing. A high-frequency network detection method, device, electronic device, and readable storage medium are provided. Background Art

[0002] Network monitoring is an essential part of modern information technology management, aiming to ensure the security, reliability, and efficient operation of the network. With the development of technologies such as cloud computing, Internet of Things, and big data, the network environment has become more complex, so an accurate and efficient monitoring solution is needed to meet different requirements.

[0003] Generally, network detection technologies between point-to-point (including two methods: low-frequency detection and high-frequency detection) are adopted to monitor the network connection status between two specific nodes in real time. However, when using the high-frequency detection method in the prior art, a large number of network connections need to be established by the source detection node, which will greatly occupy resources such as the CPU and memory of the source detection node, thus affecting the process of the source detection node obtaining the network connection status. Summary of the Invention

[0004] According to a first aspect of the present disclosure, a high-frequency network detection method is provided, which is applied to a source detection node and includes: multiplying the number of target links between the source detection node and a target detection node by a preset value to obtain a target value; creating a raw socket, and constructing a plurality of detection request packets according to the target value; sending the plurality of detection request packets to the target detection node through the raw socket for the target detection node to obtain a detection return packet according to the actually received detection request packets; receiving, through the raw socket, the detection return packet sent by the target detection node; and performing a preset process on the plurality of detection request packets and the detection return packet, and obtaining the network connection status between the source detection node and the target detection node according to the processing result.

[0005] According to a second aspect of the present disclosure, a high-frequency network detection method is provided, which is applied to a target detection node and includes: receiving a detection request packet sent by a source detection node, where the detection request packet is sent by the source detection node through a raw socket; obtaining a detection return packet according to the detection request packet, and sending the detection return packet to the source detection node for the source detection node to perform a preset process on a plurality of detection request packets and the detection return packet to obtain the network connection status between the source detection node and the target detection node.

[0006] According to a third aspect of the present disclosure, a high-frequency network detection device is provided, which is located at a source detection node and includes: a processing unit configured to use a multiplication result of a target link number between the source detection node and a target detection node and a preset value as a target value; a construction unit configured to create a raw socket and construct a plurality of detection request packets according to the target value; a first sending unit configured to send the plurality of detection request packets to the target detection node through the raw socket for the target detection node to obtain a detection response packet based on the actually received detection request packets; a second receiving unit configured to receive the detection response packet sent by the target detection node through the raw socket; and a detection unit configured to perform preset processing on the plurality of detection request packets and the detection response packet and obtain a network connection state between the source detection node and the target detection node according to a processing result.

[0007] According to a fourth aspect of the present disclosure, a high-frequency network detection device is provided, which is located at a target detection node and includes: a first receiving unit configured to receive the detection request packets sent by a source detection node, where the detection request packets are sent by the source detection node through a raw socket; and a second sending unit configured to obtain a detection response packet according to the detection request packets and send the detection response packet to the source detection node for the source detection node to perform preset processing on the plurality of detection request packets and the detection response packet to obtain a network connection state between the source detection node and the target detection node.

[0008] According to a fifth aspect of the present disclosure, an electronic device is provided, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the method as described above.

[0009] According to a sixth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause the computer to execute the method as described above.

[0010] According to a seventh aspect of the present disclosure, a computer program product is provided, including a computer program which, when executed by a processor, implements the method as described above.

[0011] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. Description of the Drawings

[0012] The accompanying drawings are used to better understand the present solution and do not limit the disclosure. Among them:

[0013] Figure 1 is a schematic diagram according to the first embodiment of the present disclosure;

[0014] Figure 2 is a schematic diagram according to the second embodiment of the present disclosure;

[0015] Figure 3 is a schematic diagram according to the third embodiment of the present disclosure;

[0016] Figure 4 is a schematic diagram according to the fourth embodiment of the present disclosure;

[0017] Figure 5 is a schematic diagram according to the fifth embodiment of the present disclosure;

[0018] Figure 6 is a schematic diagram according to the sixth embodiment of the present disclosure;

[0019] Figure 7 is a block diagram of an electronic device for implementing the high-frequency network detection method of the embodiments of the present disclosure. Detailed implementation manners

[0020] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, descriptions of well-known functions and mechanisms are omitted in the following description for clarity and conciseness.

[0021] Figure 1 is a schematic diagram according to the first embodiment of the present disclosure. As Figure 1 shown, the high-frequency network detection method of this embodiment is applied to a source detection node and specifically includes the following steps:

[0022] S101. Multiply the number of target links between the source detection node and the target detection node by a preset value to obtain a target value;

[0023] S102. Create a raw socket and construct multiple detection request packets according to the target value;

[0024] S103. Send the multiple detection request packets to the target detection node through the raw socket for the target detection node to obtain detection response packets based on the actually received detection request packets;

[0025] S104. Receive the detection response packets sent by the target detection node through the raw socket;

[0026] S105. Perform preset processing on the multiple probe request packets and the probe response packets, and obtain the network connection status between the source probe node and the target probe node according to the processing result.

[0027] The high-frequency network probing method applied to the source probe node in this embodiment, on the one hand, through the created raw socket, constructs multiple probe request packets according to the target value obtained from the preset value and the number of target links between nodes, enabling the source probe node to send a large number of probe request packets to the target probe node at the same time, so as to achieve the purpose of high-frequency network probing between nodes. On the other hand, the source probe node only uses one created raw socket to send probe request packets and receive probe response packets, without establishing multiple network connections (i.e., multiple ordinary sockets), which can reduce the resource (CPU, memory, etc.) occupancy of the source probe node, thereby improving the packet receiving performance, data processing performance, etc. of the source probe node.

[0028] The node in this embodiment can be a server, a router or other network devices; through the high-frequency network probing method provided in this embodiment, the network performance (i.e., network connection status) between specific node pairs (i.e., source probe node and target probe node) can be monitored.

[0029] When the source probe node of this embodiment executes S101, the multiplication result of the preset value and the number of target links between the source probe node and the target probe node can be used as the target value; where the target value corresponds to the number of probe request packets to be constructed through the raw socket.

[0030] In this embodiment, a link (or communication link) refers to the physical connection for data transmission between the source probe node and the target probe node. For example, if the source probe node and the target probe node perform data transmission through multiple levels of network devices (such as switches or routers), then a link between the nodes can be obtained according to different network devices located in different levels.

[0031] When the source probe node of this embodiment executes S101, the total number of links through which a data packet can reach the target probe node from the source probe node can be obtained as the target link number.

[0032] When the source detection node of this embodiment executes S101, the following method can also be used to determine the target number of links: Determine the link level between the source detection node and the target detection node; Obtain the number of links corresponding to each link level, and use the maximum number of links as the target number of links. The number of links corresponding to the link level is the number of links included in the link level; Among them, the source detection node in this embodiment can determine the link level and the number of links corresponding to each link level according to the network topology diagram between node pairs.

[0033] That is to say, this embodiment uses the maximum number of links corresponding to the link level between node pairs as the target number of links, so as to fully consider each link between node pairs, improve the accuracy of the obtained target number, and ensure that the constructed detection request packet can cover all links between node pairs, thereby realizing high-frequency network detection with full link coverage.

[0034] For example, if the obtained target number of links is 12 and the preset value is 10, then this embodiment will use 120 obtained by (12×10) as the target value; that is, this embodiment will construct multiple detection request packets according to a quantity that is 10 times the corresponding target number of links.

[0035] After the source detection node of this embodiment obtains the target value when executing S101, it executes S102 to create a raw socket and constructs multiple detection request packets according to the obtained target value; among them, the number of detection request packets constructed by the source detection node of this embodiment through the raw socket is consistent with the target value.

[0036] The raw socket (Raw Socket) created by the source detection node of this embodiment when executing S102 does not perform port binding and allows direct access to the underlying network protocol, thereby supporting the custom construction of IP data packets (i.e., detection request packets) and the sending of IP data packets.

[0037] When the source detection node of this embodiment executes S102, it can create a raw socket by calling the Socket() function.

[0038] When constructing multiple probe request packets according to the target value in step S102, the source probe node in this embodiment may adopt the following implementation method: obtain the IP header (i.e., IP Header) according to the IP (Internet Protocol) address of the source probe node (i.e., the source IP address) and the IP address of the target probe node (i.e., the target IP address); determine the first number of source ports (i.e., the ports in the source probe node) and the second number of target ports (i.e., the ports in the target probe node) according to the target value, and the product of the first number and the second number is the target value; obtain different UDP (User Datagram Protocol) headers (i.e., UDP Header) according to the first number of source ports and the second number of target ports; construct multiple probe request packets according to the IP header and different UDP headers.

[0039] That is to say, in this embodiment, through the raw socket, based on the first number of source ports and the second number of target ports determined according to the target value, the construction of multiple probe request packets is completed, so that different probe request packets include different UDP headers, and the number of constructed probe request packets is consistent with the target value, so that each link is covered by a sufficient number of probe request packets, thereby achieving the purpose of high-frequency network detection with full link coverage.

[0040] For example, if the target value is 120 and the number of target links is 12, then in step S102 of this embodiment, 120 probe request packets will be constructed through the raw socket, so that an average of 10 probe request packets are covered on each link.

[0041] In this embodiment, the first number is greater than the second number. That is, when constructing different UDP headers, the number of source ports used is relatively large, while the number of target ports used is relatively small. For example, the first number is 60 and the second number is 2, or the first number is 120 and the second number is 1.

[0042] For the convenience of management, the different source ports in the source probe node are continuous, and the different target ports in the target probe node are also continuous.

[0043] When obtaining different UDP headers according to the first number of source ports and the second number of target ports in step S102, the source probe node in this embodiment may construct different port pairs according to the first number of source ports and the second number of target ports, and then obtain different UDP headers according to the different port pairs.

[0044] In addition, when the source detection node of this embodiment executes S102, it can further obtain information such as Version, Internet Header Length (IHL), Differentiated Services Code Point (DSCP) + Explicit Congestion Notification (ECN), Total Length, Identification, Time To Live (TTL), and Protocol, and then combine the source IP address and the destination IP address to obtain different IP headers.

[0045] In this embodiment, different DSCP (Differentiated Services Code Point) values can be set to detect the communication quality of different service types (different DSCP values correspond to different service types).

[0046] When the source detection node of this embodiment constructs multiple probe request packets according to the IP header and different UDP headers in S102, it may further include the following: obtaining the payload, where the payload includes a timestamp, a sequence number (for example, using the identification in the IP header as the sequence number), and data in binary format (such as multiple bytes of data like (0, 0, 0, 0, 1), (0, 1, 0, 1, 0, 1), etc.). Different payloads may include the same data or different data; constructing multiple probe request packets according to the IP header, different UDP headers, and the payload.

[0047] That is to say, this embodiment can also include a payload in the constructed probe request packet, and then determine whether there is a behavior of modifying the packet (such as whether the data in the payload is modified) according to the payload included in the probe request packet, improving the applicable scenarios of high-frequency network detection.

[0048] After the source detection node of this embodiment constructs multiple probe request packets in S102, it executes S103 to send the multiple probe request packets to the target detection node through a raw socket.

[0049] When the source detection node of this embodiment executes S103, through the raw socket, according to the destination IP address and destination port in the probe request packet, it sends the probe request packet to the corresponding port on the target detection node.

[0050] The source detection node of this embodiment constructs far more probe request packets than the number of target links, and sends a large number of probe request packets to the target detection node at the same time, which can achieve the purpose of high-frequency network detection, and a large number of probe request packets can cover all the links between the source detection node and the target detection node, further achieving the purpose of high-frequency network detection with full link coverage, thereby improving the accuracy and comprehensiveness of network detection.

[0051] In addition, the source detection node of this embodiment only needs to construct one raw socket to send a large number of detection request packets to the target detection node, without establishing a network connection (i.e., a normal socket) corresponding to each detection request packet, thus greatly reducing the number of established network connections and avoiding the problem of a large number of network connections occupying the resources of the source detection node.

[0052] The detection request packets sent by the source detection node of this embodiment to the target detection node through the raw socket are used for the target detection node to obtain detection response packets according to the actually received detection request packets.

[0053] After the source detection node of this embodiment executes S103 to send multiple detection request packets to the target detection node through the raw socket, it executes S104 to receive the detection response packets sent by the target detection node through the raw socket.

[0054] After the source detection node of this embodiment finishes sending the detection request packets, it can, according to the created raw socket, receive the detection response packets returned from the target detection node, and then obtain the network connection status between the nodes according to the detection request packets and the received detection response packets.

[0055] In this embodiment, the source detection node creates a raw socket. Based on the inherent characteristics of the raw socket, in addition to receiving the detection response packets sent by the target detection node, the source detection node will also receive other data packets sent by other nodes through this raw socket.

[0056] After the source detection node of this embodiment executes S104 to receive the detection response packets sent by the target detection node through the raw socket, it executes S105 to perform preset processing on the multiple detection request packets and detection response packets, and obtain the network connection status between the source detection node and the target detection node according to the processing results.

[0057] In this embodiment, the obtained network connection status can be network performance indicators such as network packet loss rate, network jitter, network delay, and network security; the obtained network connection status can also be a network performance level further determined according to the above network performance indicators. For example, an excellent network performance level is obtained when the network packet loss rate is small, and a poor network performance level is obtained when the network delay is large, etc.

[0058] When the source detection node of this embodiment executes S105, it can first determine the detection request packet corresponding to each detection response packet (which can also be called the target detection request packet) from multiple detection request packets. For example, it can be determined by the preset identification information of the data packet (different detection request packets have different preset identification information, and this preset identification information remains unchanged during the transmission process), or the sequence number in the payload. Then, preset processing is performed on the detection response packet and its corresponding detection request packet, so as to obtain the network connection status between nodes according to the processing result.

[0059] For example, the preset processing performed by the source detection node of this embodiment when executing S105 can be processing for calculating network delay, that is, calculating the time difference between the reception time when receiving the detection response packet and the transmission time when sending the detection request packet corresponding to this detection response packet (the transmission time can be determined according to the timestamp in the payload), and taking the calculation result as the network delay between nodes.

[0060] Another example is that the preset processing performed by the source detection node of this embodiment when executing S105 can also be processing for calculating network packet loss rate, that is, calculating the ratio between the number of received detection response packets and the number of sent detection request packets, and taking the calculation result as the network packet loss rate between nodes.

[0061] Still another example is that the preset processing performed by the source detection node of this embodiment when executing S105 can also be processing for network security, that is, comparing the data included in the payload of the received detection response packet (which can be called return data) with the data included in the payload of the detection request packet corresponding to this detection response packet (which can be called request data). If they are the same, it is determined that there is no packet modification behavior and the network security between nodes is relatively high. If they are different, it is determined that there is a packet modification behavior and the network security between nodes is relatively low.

[0062] In addition, since the source detection node will also receive other data packets sent by other nodes through the created raw socket, which will affect the processing efficiency when processing the detection response packet and its corresponding detection request packet. Before the source detection node of this embodiment executes S105, the following content can also be included: filtering non-detection response packets (that is, detection response packets not sent by the target detection node) through a pre-set filtering program, for example, filtering according to the preset identification information of the data packet.

[0063] In this embodiment, the filtering program set by the source detection node may be a BPF (Berkeley Packet Filter) program, which allows custom rules to determine which data packets should be passed to the application in the user space for processing; in this embodiment, custom rules can be set to only allow the detection response packets sent by the target server to be passed to the application in the user space to determine the network connection status.

[0064] It can be understood that compared with low-frequency network detection, high-frequency network detection (i.e., the detection method of sending a large number of detection request packets in a short time) can solve the problem that it is difficult to monitor minor and occasional packet losses, and can also more quickly check abnormal network connection states such as packet loss anomalies and latency anomalies.

[0065] Figure 2 It is a schematic diagram according to the second embodiment of the present disclosure. As Figure 2 shown, the high-frequency network detection method of this embodiment is applied to the target detection node, and specifically includes the following steps:

[0066] S201. Receive the detection request packet sent by the source detection node, where the detection request packet is sent by the source detection node through the raw socket;

[0067] S202. Obtain the detection response packet according to the detection request packet, and send the detection response packet to the source detection node for the source detection node to perform preset processing on multiple detection request packets and the detection response packet to obtain the network connection state between the source detection node and the target detection node.

[0068] The high-frequency network detection method of this embodiment applied to the target detection node obtains the detection response packet according to the detection request packet sent by the source detection node through the raw socket, so that the source detection node corresponding to the target detection node can determine the network connection state according to the received detection response packet, thereby achieving the purpose of high-frequency network detection between nodes.

[0069] This embodiment makes relatively small changes to the target detection node. Since the source detection node uses a smaller number of target ports when constructing different detection request packets, the target detection node in this embodiment can use a conventional UDP program to receive the detection request packet and send the detection response packet.

[0070] When the target detection node in this embodiment executes S202 to obtain a detection response packet based on the detection request packet, it does not make any modifications to the received detection request packet. Instead, based on the basic principles of network communication, it exchanges the source IP address and the target IP address in the detection request packet, exchanges the source port and the target port, and then obtains the corresponding detection response packet. Furthermore, it accurately sends the detection response packet to the source detection node.

[0071] Figure 3 It is a schematic diagram according to the third embodiment of the present disclosure. Figure 3 shows the network topology between the source detection node and the target detection node: In Figure 3 among them, devices 1 to 8 between the source detection node and the target detection node are network devices, such as switches or routers; specifically, the source detection node and (devices 1, 2) form link layer 1, (devices 1, 2) and (devices 3, 4, 5, 6) form link layer 2, (devices 3, 4, 5, 6) and (devices 7, 8) form link layer 3, and (devices 7, 8) and the target detection node form link layer 4.

[0072] Figure 3 The line segments between the link layers in it represent links, and the number of line segments is the number of links in that layer; for example, the number of links in link layer 1 is 2, the number of links in link layer 2 is 12, the number of links in link layer 3 is 12, and the number of links in link layer 4 is 2; this embodiment can use 12 as the target number of links. If the preset value is 10, the source detection node in this embodiment will construct 120 detection request packets, so that an average of 10 detection request packets cover each link.

[0073] It can be understood that since the source detection node needs to send 120 detection request packets to the target detection node, if the conventional method is used, 120 ordinary Sockets need to be created by the source detection node, and the number of established Sockets is relatively large; while using the solution provided by this embodiment, the source detection node only needs to create one Raw Socket to send 120 detection request packets, thus greatly reducing the number of Sockets that the source detection node needs to create.

[0074] Figure 4 It is a schematic diagram according to the fourth embodiment of the present disclosure. Figure 4An application flowchart of the high-frequency network detection method according to this embodiment is shown as follows: S401. In response to receiving a high-frequency network detection request, perform a high-frequency network detection process between the source detection node and the target detection node. The high-frequency network detection request in this embodiment can be automatically initiated at a preset time interval or initiated after detecting that the user triggers the corresponding request button. The high-frequency network detection process between the source detection node and the target detection node is the process corresponding to S101-S105 and S201-S202 above; S402. Obtain the network connection status corresponding to the high-frequency network detection request; S403. Obtain a preset network connection status, and compare the network connection status with the preset network connection status (such as preset packet loss rate, preset delay, etc.); S404. In response to determining that the comparison result meets the preset requirements, send out a warning message to prompt the network administrator.

[0075] For example, when this embodiment executes S403, it can compare the obtained packet loss rate with the preset packet loss rate. If the packet loss rate is greater than the preset packet loss rate, it is determined that the comparison result meets the preset requirements; it can also compare the obtained delay with the preset delay. If the delay is greater than the preset delay, it is determined that the comparison result meets the preset requirements.

[0076] Figure 5 is a schematic diagram according to the fifth embodiment of the present disclosure. As Figure 5 shown, the high-frequency network detection device 500 of this embodiment is located at the source detection node and includes:

[0077] A processing unit 501, configured to use the multiplication result of the number of target links between the source detection node and the target detection node and a preset value as the target value;

[0078] A construction unit 502, configured to create a raw socket and construct a plurality of detection request packets according to the target value;

[0079] A first sending unit 503, configured to send the plurality of detection request packets to the target detection node through the raw socket, so that the target detection node obtains a detection return packet according to the actually received detection request packets;

[0080] A second sending unit 504, configured to receive the detection return packets sent by the target detection node through the raw socket;

[0081] A detection unit 505, configured to perform preset processing on the plurality of detection request packets and the detection return packets, and obtain the network connection status between the source detection node and the target detection node according to the processing result.

[0082] The processing unit 501 may use the result of multiplying a preset value and the number of target links between the source detection node and the target detection node as the target value; wherein, the target value corresponds to the number of detection request packets to be constructed through the raw socket.

[0083] In this embodiment, a link (or communication link) refers to a physical connection for data transmission between a source detection node and a target detection node. For example, if the source detection node and the target detection node perform data transmission through multiple levels of network devices (such as switches or routers), then a link between the nodes can be obtained according to different network devices located at different levels.

[0084] The processing unit 501 may obtain the total number of links through which a data packet can reach the target detection node from the source detection node as the target link number.

[0085] The processing unit 501 may also determine the target link number in the following manner: determine the link levels between the source detection node and the target detection node; obtain the number of links corresponding to each link level, and use the maximum number of links as the target link number. The number of links corresponding to a link level is the number of links included in the link level; wherein, in this embodiment, the source detection node may determine the link levels and the number of links corresponding to each link level according to the network topology diagram between node pairs.

[0086] That is to say, the processing unit 501 uses the maximum number of links corresponding to the link levels between node pairs as the target link number, thereby fully considering each link between node pairs, which can improve the accuracy of the obtained target quantity and ensure that the constructed detection request packets can cover all links between node pairs, and further realize high-frequency network detection with full link coverage.

[0087] After the source detection node of this embodiment obtains the target value by the processing unit 501, the construction unit 502 creates a raw socket and constructs multiple detection request packets according to the obtained target value; wherein, the number of detection request packets constructed by the construction unit 502 is consistent with the target value.

[0088] The raw socket created by the construction unit 502 (Raw Socket) does not perform port binding and allows direct access to the underlying network protocol, thereby supporting the custom construction of IP data packets (i.e., detection request packets) and the sending of IP data packets.

[0089] The construction unit 502 may create a raw socket by calling the Socket() function.

[0090] When constructing multiple probe request packets according to the target value, the implementation method that the construction unit 502 can adopt is as follows: obtain the IP header (i.e., IP Header) according to the IP (Internet Protocol) address of the source probe node (i.e., the source IP address) and the IP address of the target probe node (i.e., the target IP address); determine the first number of source ports (i.e., the ports in the source probe node) and the second number of target ports (i.e., the ports in the target probe node) according to the target value, and the multiplication result between the first number and the second number is the target value; obtain different UDP (User Datagram Protocol) headers (i.e., UDP Header) according to the first number of source ports and the second number of target ports; construct multiple probe request packets according to the IP header and different UDP headers.

[0091] That is to say, the construction unit 502 completes the construction of multiple probe request packets through the raw socket, based on the first number of source ports and the second number of target ports determined according to the target value, so that different probe request packets include different UDP headers, and the number of constructed probe request packets is consistent with the target value, so that each link is covered by a sufficient number of probe request packets, achieving the purpose of high-frequency network detection with full link coverage.

[0092] In this embodiment, the first number is greater than the second number, that is, when constructing different UDP headers, the number of source ports used is larger, and the number of target ports used is smaller. For example, the first number is 60 and the second number is 2, or the first number is 120 and the second number is 1.

[0093] For the convenience of management, different source ports in the source probe node are continuous, and different target ports in the target probe node are also continuous.

[0094] When the construction unit 502 obtains different UDP headers according to the first number of source ports and the second number of target ports, it can construct different port pairs according to the first number of source ports and the second number of target ports, and then obtain different UDP headers according to different port pairs.

[0095] In addition, the construction unit 502 can further obtain information such as version, header length (IHL), differentiated services code point + explicit congestion notification (DSCP+ECN), total length, identification, time to live (TTL), protocol, etc., and then combine the source IP address and the target IP address to obtain different IP headers.

[0096] In this embodiment, different DSCP (Differentiated Services Code Point) values can be set to detect the communication quality of different service types (different DSCP values correspond to different service types).

[0097] When constructing multiple probe request packets according to the IP header and different UDP headers, the construction unit 502 may further include the following: obtaining the payload, where the payload includes a timestamp, a sequence number (for example, using the identification in the IP header as the sequence number), and data in binary format. Different payloads may include the same data or different data; constructing multiple probe request packets according to the IP header, different UDP headers, and the payload.

[0098] That is to say, the construction unit 502 may also include the payload in the constructed probe request packets, so as to determine whether there is a behavior of modifying the packet (for example, whether the data in the payload is modified) according to the payload included in the probe request packets, and improve the applicable scenarios of high-frequency network detection.

[0099] After the source detection node of this embodiment constructs multiple probe request packets by the construction unit 502, the first sending unit 503 sends the multiple probe request packets to the target detection node through the raw socket.

[0100] The first sending unit 503 sends the probe request packet to the corresponding port on the target detection node through the raw socket according to the target IP address and target port in the probe request packet.

[0101] The source detection node of this embodiment constructs far more probe request packets than the number of target links, and sends a large number of probe request packets to the target detection node at the same time, which can achieve the purpose of high-frequency network detection, and a large number of probe request packets can cover all links between the source detection node and the target detection node, further achieving the purpose of high-frequency network detection with full link coverage, thereby improving the accuracy and comprehensiveness of network detection.

[0102] The probe request packet sent by the source detection node of this embodiment to the target detection node through the raw socket is used for the target detection node to obtain the probe response packet according to the actually received probe request packet.

[0103] After the source detection node of this embodiment sends multiple probe request packets to the target detection node through the raw socket by the first sending unit 503, the second receiving unit 504 receives the probe response packet sent by the target detection node through the raw socket.

[0104] After the source detection node of this embodiment finishes sending the detection request packet, it can receive the detection response packet returned from the target detection node according to the created raw socket, and then obtain the network connection status between nodes based on the detection request packet and the received detection response packet.

[0105] In this embodiment, the source detection node creates a raw socket. Based on the characteristics of the raw socket itself, in addition to receiving the detection response packet sent by the target detection node, the source detection node will also receive other data packets sent by other nodes through this raw socket.

[0106] After the source detection node of this embodiment receives the detection response packet sent by the target detection node through the raw socket by the second receiving unit 504, the detection unit 505 performs preset processing on multiple detection request packets and detection response packets, and obtains the network connection status between the source detection node and the target detection node according to the processing result.

[0107] In this embodiment, the network connection status obtained by the detection unit 505 can be network performance indicators such as network packet loss rate, network jitter, network delay, network security, etc., or can also be a network performance level further determined according to the above network performance indicators.

[0108] The detection unit 505 can first determine the detection request packet corresponding to each detection response packet (also called the target detection request packet) from multiple detection request packets. For example, it can be determined through the preset identification information of the data packet (different detection request packets have different preset identification information, and this preset identification information remains unchanged during the transmission process), or the sequence number in the payload, and then perform preset processing on the detection response packet and its corresponding detection request packet, and obtain the network connection status between nodes according to the processing result.

[0109] In addition, since the source detection node will also receive other data packets sent by other nodes through the created raw socket, it will affect the processing efficiency when processing the detection response packet and its corresponding detection request packet. The detection unit 505 can also include the following content: filtering non-detection response packets (that is, detection response packets not sent by the target detection node) through a pre-set filtering program, for example, filtering according to the preset identification information of the data packet.

[0110] The detection unit 505 can also perform the following content: after obtaining the network connection status between the source detection node and the target detection node, obtain the preset network connection status; compare the network connection status with the preset network connection status; in response to determining that the comparison result meets the preset requirements, issue a warning message.

[0111] Figure 6 It is a schematic diagram according to the sixth embodiment of the present disclosure. AsFigure 6 As shown, the high-frequency network detection device 600 of this embodiment is located at the target detection node and includes:

[0112] A first receiving unit 601, configured to receive a detection request packet sent by a source detection node, where the detection request packet is sent by the source detection node through a raw socket;

[0113] A second sending unit 602, configured to obtain a detection response packet according to the detection request packet, and send the detection response packet to the source detection node, so that the source detection node performs preset processing on multiple detection request packets and the detection response packet to obtain the network connection status between the source detection node and the target detection node.

[0114] This embodiment makes less modification to the target detection node. Since the source detection node uses a smaller number of target ports when constructing different detection request packets, the target detection node in this embodiment can use a conventional UDP program to receive detection request packets and send detection response packets.

[0115] When obtaining the detection response packet according to the detection request packet, the second sending unit 602 does not make any modification to the received detection request packet, but only exchanges the source IP address and the target IP address in the detection request packet and exchanges the source port and the target port based on the basic principles of network communication to obtain the corresponding detection response packet, and then accurately sends the detection response packet to the source detection node.

[0116] In the technical solution of the present disclosure, the acquisition, storage, and application of the user's personal information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0117] According to the embodiments of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0118] As Figure 7 shown, it is a block diagram of an electronic device for a high-frequency network detection method according to an embodiment of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processing device, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0119] As Figure 7As shown, device 700 includes a computing unit 701, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of device 700 can also be stored. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0120] Multiple components in device 700 are connected to the I / O interface 705, including: an input unit 706, such as a keyboard, a mouse, etc.; an output unit 707, such as various types of displays, speakers, etc.; a storage unit 708, such as a disk, an optical disc, etc.; and a communication unit 709, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 709 allows device 700 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0121] The computing unit 701 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 701 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 701 executes the various methods and processes described above, such as the high-frequency network detection method. For example, in some embodiments, the high-frequency network detection method can be implemented as a computer software program, which is tangibly included in a machine-readable medium, such as the storage unit 708.

[0122] In some embodiments, part or all of the computer program can be loaded and / or installed onto device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded into the RAM 703 and executed by the computing unit 701, one or more steps of the high-frequency network detection method described above can be executed. Alternatively, in other embodiments, the computing unit 701 can be configured to execute the high-frequency network detection method in any other appropriate way (e.g., by means of firmware).

[0123] The various embodiments of the systems and techniques described herein can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0124] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable vehicle positioning or positioning model training device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.

[0125] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can include or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0126] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for presenting information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0127] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0128] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The relationship of the client and the server is generated by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services ("Virtual Private Server", or simply "VPS"). The server can also be a server of a distributed system, or a server combined with a blockchain.

[0129] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and no limitation is made herein.

[0130] The above specific embodiments do not constitute a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present disclosure shall be included within the protection scope of the present disclosure.

Claims

1. A high-frequency network detection method, applied to a source detection node, comprising: The result of multiplying the target link number between the source detection node and the target detection node by a preset value is used as the target value; Creating a raw socket, and constructing multiple probe request packets according to the target value; Sending the plurality of detection request packets to the target detection node through the original socket, so that the target detection node obtains a detection return packet according to the detection request packets actually received; Receiving a detection return packet sent by the target detection node through the original socket; The plurality of detection request packets and the detection return packets are processed in a preset manner, and the network connection status between the source detection node and the target detection node is obtained according to the processing result.

2. The method according to claim 1, wherein: The multiplication result of the target link number between the source detection node and the target detection node and a preset value as the target value includes: Determining a link level between the source detection node and the target detection node; Obtain the number of links corresponding to each link level, and use the maximum number of links as the target number of links; The multiplication result of the preset value and the target link number is used as the target value.

3. The method according to claim 1, wherein: The constructing a plurality of detection request packets according to the target value comprises: Obtaining an IP header according to the IP address of the source detection node and the IP address of the target detection node; Determining a first number of source ports and a second number of target ports according to the target value; Obtain different UDP headers according to the first number of source ports and the second number of destination ports; The multiple probe request packets are constructed according to the IP header and the different UDP headers.

4. The method according to claim 3, wherein: The constructing the plurality of probe request packets according to the IP header and the different UDP headers comprises: Get the payload; The multiple probe request packets are constructed according to the IP header, the different UDP headers and the payload.

5. The method according to claim 1, further comprising: Before performing preset processing on the multiple detection request packets and the detection return packets, non-detection return packets are filtered through a preset filtering program.

6. The method according to claim 1, further comprising: After obtaining the network connection state between the source detection node and the target detection node according to the processing result, obtaining a preset network connection state; Comparing the network connection status with the preset network connection status; In response to determining that the comparison result meets the preset requirement, a warning message is issued.

7. A high frequency network detection method, applied to a target detection node, comprising: Receiving a detection request packet sent by a source detection node, wherein the detection request packet is sent by the source detection node through a raw socket; A detection return packet is obtained according to the detection request packet, and the detection return packet is sent to the source detection node, so that the source detection node performs preset processing on multiple detection request packets and the detection return packet to obtain the network connection status between the source detection node and the target detection node.

8. A high frequency network detection device, located at a source detection node, comprising: A processing unit, configured to use a multiplication result of the target link number between the source detection node and the target detection node and a preset value as a target value; A construction unit, used to create a raw socket and construct a plurality of probe request packets according to the target value; A first sending unit, configured to send the plurality of detection request packets to the target detection node through the original socket, so that the target detection node obtains a detection return packet according to the actually received detection request packets; A second receiving unit, configured to receive a detection return packet sent by the target detection node through the original socket; The detection unit is used to perform preset processing on the multiple detection request packets and the detection return packets, and obtain the network connection status between the source detection node and the target detection node according to the processing result.

9. A high-frequency network detection device, located at a target detection node, comprising: A first receiving unit, configured to receive a detection request packet sent by a source detection node, wherein the detection request packet is sent by the source detection node through a raw socket; A second sending unit is used to obtain a detection return packet according to the detection request packet, and send the detection return packet to the source detection node, so that the source detection node performs preset processing on multiple detection request packets and the detection return packet to obtain the network connection status between the source detection node and the target detection node.

10. An electronic device, comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can perform the method according to any one of claims 1 to 7.

11. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 7.

12. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method according to any one of claims 1 to 7.