A method and apparatus for route state awareness through distributed network probe collaborative monitoring
By deploying distributed probe devices in 5G/6G networks, combining active detection and passive listening, and dynamically adjusting the detection mode, the issues of accuracy and resource overhead in network status perception are resolved, achieving efficient and accurate network status monitoring.
Patent Information
- Application Number
- CN202510754709.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-06-06
AI Technical Summary
Existing network detection technologies struggle to achieve efficient, accurate, and low-overhead network status awareness in 5G/6G environments. The deployment density of detection equipment does not match the network slicing requirements, the detection triggering mechanism and target selection strategy are difficult to adjust dynamically, and data fusion and analysis methods are insufficient, resulting in insufficient detection accuracy and excessive resource consumption.
Distributed probe devices are deployed at multiple key nodes in 5G/6G networks. Combining active detection and passive monitoring, the detection mode is dynamically adjusted and resources are optimized through periodic and targeted detection, data fusion analysis units, and reinforcement learning models.
It significantly improves the accuracy and real-time performance of network status awareness, reduces resource consumption, ensures timely monitoring of critical links and business needs, and enhances the sensitivity and accuracy of network detection.
Smart Images

Figure CN120567748B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication network monitoring technology, and in particular to a method and apparatus for route status perception in collaborative monitoring of distributed network probes. Background Technology
[0002] With the rapid development and widespread deployment of fifth-generation (5G) and sixth-generation (6G) mobile communication technologies, network services are becoming increasingly diverse, application scenarios are constantly expanding, and the number of network access devices is growing exponentially. At the same time, the emergence of various real-time sensitive services, ultra-reliable low-latency communication (URLLC), and massive machine-type communication (mMTC) demands have placed higher requirements on the accuracy and real-time performance of network routing status awareness. How to achieve efficient, accurate, and low-overhead network status awareness and fault tracing has become a critical issue that urgently needs to be addressed.
[0003] In recent years, network probing technology has developed rapidly, gradually forming network state awareness methods represented by active probing and passive monitoring. Active probing methods directly measure network links by actively sending probe packets, enabling rapid and accurate detection of link status, but incur additional bandwidth consumption and are prone to network congestion. Passive monitoring methods, on the other hand, perceive network traffic characteristics in real time through traffic monitoring and deep packet inspection (DPI) technology, achieving low-overhead state monitoring and fault tracing, but their accuracy is easily affected by network traffic fluctuations and differences in service types. Therefore, how to balance the real-time advantages of active probing and the low-overhead advantages of passive monitoring to achieve a dynamic balance in network state awareness has gradually become a hot research topic.
[0004] Currently, existing network detection technologies still face several challenges: First, there is the issue of adapting the deployment density of detection equipment to the needs of network slicing, particularly the allocation of detection resources for different slicing scenarios such as URLLC and mMTC. Second, the triggering mechanism and target selection strategy for detection are difficult to dynamically adjust according to network status, affecting the efficiency and accuracy of detection. Third, data fusion and analysis methods are insufficient, making it impossible to effectively utilize data obtained from different detection methods for comprehensive analysis. Therefore, to meet the needs of accurate network status perception and efficient fault tracing in 5G / 6G network environments, there is an urgent need to design an intelligent network detection method suitable for the coordinated operation of active detection and passive monitoring, in order to solve the balance between detection accuracy and resource overhead.
[0005] Network probing introduces a collaborative mechanism of active detection and passive monitoring, deploying distributed probes to achieve comprehensive network status awareness. Active detection provides high real-time link status awareness by dynamically adjusting detection frequency and target node selection, but it also incurs certain network resource consumption. Passive monitoring, on the other hand, analyzes existing network traffic to locate faults and trace data sources, but its real-time response capability to network status is relatively limited. Currently, combining the advantages of both detection methods to achieve real-time, accurate, and resource-efficient network status awareness remains a technical challenge.
[0006] Furthermore, existing detection and control technologies suffer from insufficient intelligent decision-making capabilities, making it difficult to adjust detection modes and strategies in real time according to dynamically changing network conditions. Traditional data fusion methods also struggle to effectively integrate data from active detection and passive monitoring, failing to fully leverage the advantages of collaborative detection. While existing detection technologies, such as fault tracing methods based on Bayesian networks and machine learning, have been extensively studied, these technologies still require further adaptive optimization for the characteristics of 5G / 6G networks. Therefore, there is an urgent need to design network detection schemes suitable for distributed network environments, capable of intelligently coordinating active detection and passive monitoring, and achieving efficient data fusion and dynamic decision-making to comprehensively improve the accuracy and efficiency of network state awareness. Summary of the Invention
[0007] In view of this, embodiments of the present invention provide a route status awareness method and apparatus for distributed network probe collaborative monitoring, in order to solve the problems of existing network detection technologies such as low detection accuracy, insufficient data fusion, and single control strategy, especially to achieve efficient, intelligent, and low-overhead link status awareness and monitoring in 5G / 6G environments.
[0008] On one hand, the present invention provides a route state awareness method for distributed network probe collaborative monitoring, characterized in that the method includes the following steps:
[0009] The method involves deploying distributed probe devices on multiple key nodes of the 5G / 6G network. The probe devices include an active detection module, a passive traffic monitoring module, a data fusion analysis unit, and a detection control module.
[0010] The active detection module provides two detection triggering methods: periodic detection and targeted detection. Specifically:
[0011] The periodic detection method is based on a dynamically adjusted detection frequency that is triggered periodically, and the priority detection targets are determined by the calculated detection priority. Each node maintains a neighbor node detection value table, which records the unique ID of the neighbor node, the timestamp of the last detection, the detection value, the detection timeout counter, and the detection anomaly count.
[0012] In the detection value table, the detection value increases over time and satisfies a set growth formula. The periodic detection interval is inversely proportional to the number of neighboring nodes. A fixed number of neighboring nodes are selected for detection within each detection period, and the targets are sorted according to the detection priority calculation formula.
[0013] The specified detection method is used to actively send detection messages to the target path or node to form supplementary information when a specific network event occurs or when passive listening is triggered.
[0014] The passive traffic monitoring module utilizes DPI and fingerprint recognition technology to monitor business flows in real time. It constructs a conditional probability graph of node and link states based on a Bayesian network and performs fault location through a message passing algorithm. Furthermore, it uses joint modeling based on graph neural networks (GNNs) and spatiotemporal features to achieve source tracing and path identification of abnormal events. In anti-source tracing scenarios, additional probes are dynamically deployed based on identified risks.
[0015] The data fusion and analysis unit, based on the NWDAF (Non-Dual Data Analysis) function of 5G / 6G networks, aggregates data sources from both active and passive modules. Through time alignment and spatial mapping, it achieves fusion to construct a multi-dimensional state graph: nodes represent devices, edges represent links, and attributes include link latency, bandwidth utilization, and anomaly activity. This graph supports graphical display and can provide policy outputs for path reconfiguration, resource adjustment, and early warning control.
[0016] The detection control module establishes a state space (overall link load, anomaly prediction probability, resource consumption ratio, historical detection effect, etc.), action space (selection of active, passive or fusion mode) and reward function (comprehensive detection effect, resource consumption, mode switching cost) based on reinforcement learning. It uses a deep reinforcement learning model to train the optimal strategy, judges the network state in real time during operation and executes the optimal detection mode selection to achieve a dynamic balance between detection overhead and detection effect.
[0017] In some embodiments of the present invention, the method further includes:
[0018] The deployment density of the distributed probe devices is dynamically adjusted according to the 5G / 6G network slice type. Specifically, this includes: implementing a probe density doubling strategy for Ultra-Reliable Low-Latency Communication (URLLC) slices. This strategy is based on a slice criticality assessment model: the density coefficient is determined by the slice's latency sensitivity level, bandwidth requirements, and dynamic adjustment parameters; deploying probe relay arrays at the edge nodes of the URLLC slice to form redundant coverage; and implementing a probe cluster polling mechanism for massive Machine-Type Communication (mMTC) slices. When base station handover or path rerouting is detected, probe migration is automatically triggered to ensure critical path coverage.
[0019] The neighbor node detection value table management rules of the active detection module are as follows: Each piece of information corresponds to a neighbor node, recording the node ID, last detection time, current detection value, detection timeout counter, and detection anomaly count. When a node returns a detection result, the record is updated and the anomaly count is cleared; if the detection times out and the anomaly count exceeds the threshold, anomaly information is reported and its detection value is set to zero.
[0020] When detecting malicious activity paths, the passive monitoring module deploys probes at upstream and downstream nodes of the abnormal path to build high spatial resolution detection coverage for anomaly capture and in-depth monitoring.
[0021] The data fusion and analysis unit includes a strategy feedback mechanism: based on the current map status and historical trends, it infers and generates control suggestions such as path reconfiguration, slice resource adjustment, or anomaly warning.
[0022] The reinforcement learning model in the detection control module can continuously self-optimize through online training and feedback reinforcement mechanisms, and dynamically reduce the detection frequency or range according to the stability of the network state, or encrypt the detection task when the network anomaly risk increases, thereby improving the network's perception and response capabilities.
[0023] On the other hand, the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the routing state intelligent perception method based on active and passive detection fusion, data intelligent fusion analysis and reinforcement learning strategy control as described above.
[0024] The beneficial effects of the present invention are at least as follows:
[0025] This invention provides a route status awareness method and apparatus for distributed network probe collaborative monitoring, comprising: deploying distributed probe devices at multiple key nodes to complete collaborative monitoring of active detection and passive listening, based on the link status awareness requirements in a 5G / 6G network environment; performing spatiotemporal fusion analysis of heterogeneous detection data to generate an accurate network status map, based on the requirements of detection data fusion; and dynamically adjusting the detection strategy based on a reinforcement learning model to achieve optimal selection of the detection mode, based on the dynamic characteristics of network changes. The method provided by this invention integrates active detection and passive listening technologies with a reinforcement learning intelligent decision-making model, solving the bottleneck problems of insufficient detection accuracy, excessive resource consumption, and difficulty in data fusion in existing technologies, significantly improving the accuracy and real-time performance of network status awareness, while effectively reducing detection resource consumption.
[0026] Furthermore, this invention designs a dynamic network probe deployment mechanism to perform differentiated probe deployment and scheduling for different network slice types (such as URLLC and mMTC) to ensure that critical links and business requirements are monitored in a timely manner; it designs a probe value management mechanism to accurately manage the probe priority of neighboring nodes to ensure efficient resource utilization; and it designs an adaptive probe mechanism for anti-source tracing scenarios to accurately locate abnormal paths in the network and respond quickly, thereby further improving the sensitivity and accuracy of network probes.
[0027] Additional advantages, objects, and features of the invention will be set forth in part in the description which follows, and will in part become apparent to those skilled in the art upon studying the text, or may be learned by practice of the invention. The objects and other advantages of the invention can be realized and obtained through the structures specifically pointed out in the description and drawings.
[0028] Those skilled in the art will understand that the objectives and advantages of the present invention are not limited to those specifically described above, and that the above and other objectives that the present invention can achieve will be more clearly understood from the following detailed description. Attached Figure Description
[0029] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, are not intended to limit the scope of the invention. In the drawings:
[0030] Figure 1 This is a flowchart illustrating a routing state awareness method based on distributed network probe collaborative monitoring in one embodiment of the present invention.
[0031] Figure 2 This is a schematic diagram of the overall structure and network deployment of a distributed network probe device in one embodiment of the present invention.
[0032] Figure 3 This is a schematic diagram illustrating the specific workflow of the active detection module in one embodiment of the present invention.
[0033] Figure 4 This is a schematic diagram of an anomaly detection and source tracing analysis process based on passive listening in one embodiment of the present invention.
[0034] Figure 5 This is a schematic diagram of the fusion analysis, graph generation, and intelligent control decision-making process structure in one embodiment of the present invention. Detailed Implementation
[0035] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the embodiments and accompanying drawings. Here, the illustrative embodiments and descriptions of this invention are used to explain the invention, but are not intended to limit the invention.
[0036] It should also be noted that, in order to avoid obscuring the invention with unnecessary details, only the structures and / or processing steps closely related to the solution according to the invention are shown in the accompanying drawings, while other details that are not closely related to the invention are omitted.
[0037] It should be emphasized that the term "including / comprises" as used herein refers to the presence of a feature, element, step, or component, but does not exclude the presence or addition of one or more other features, elements, steps, or components.
[0038] It should also be noted that, unless otherwise specified, the term "connection" in this article can refer not only to a direct connection, but also to an indirect connection involving an intermediary.
[0039] In the following description, embodiments of the invention will be illustrated with reference to the accompanying drawings. In the drawings, the same reference numerals represent the same or similar parts, or the same or similar steps.
[0040] To address the problems of unclear deployment methods, excessive resource consumption, insufficient accuracy, and ineffective integration of active and passive detection in existing distributed network probes in 5G / 6G network environments, this invention provides a route state awareness method and apparatus for collaborative monitoring of distributed network probes. Figure 1 The process shown includes the following steps:
[0041] Step S101: Deploy a distributed probe device, which includes an active detection module, a passive listening module, a data fusion analysis unit, and a detection control module, at multiple key network nodes.
[0042] Step S102: The active detection module supports periodic detection and targeted detection. The former dynamically adjusts the detection frequency and selects the target node based on the neighbor node detection value table, while the latter cooperates with passive listening to perform path-specific detection.
[0043] In step S103, the passive monitoring module uses deep packet inspection and traffic fingerprinting methods, combined with an improved Bayesian network and machine learning model, to achieve business flow monitoring, fault location and anomaly tracing.
[0044] Step S104: The data fusion analysis unit, based on the NWDAF architecture, collects probe information and constructs a dynamic routing state map through spatiotemporal alignment. It uses network devices as nodes, links as edges, and state attributes as weights to depict the network operation status.
[0045] In step S105, the detection control module introduces a decision model based on reinforcement learning. Based on state characteristics such as network load, anomaly prediction, resource consumption ratio, and historical detection results, it realizes intelligent scheduling and switching of three detection modes: active, passive, and active-passive fusion, and dynamically balances detection accuracy and network overhead.
[0046] like Figure 2 As shown, this invention relates to a distributed network probe device and its deployment method suitable for fifth-generation (5G) and sixth-generation (6G) mobile communication network environments. This embodiment mainly includes the deployment location, structure and functional modules of the distributed probe device, the direction of probe data flow, the decision control mechanism, and the probe density and dynamic deployment strategy within network slices. Specifically, as shown in the figure, the distributed network probe device is deployed on multiple key network nodes of the 5G / 6G network and is classified and deployed according to the network slice type, including ultra-reliable low-latency communication (URLLC) slices, massive machine-type communication (mMTC) slices, and ordinary communication slices.
[0047] In URLLC slicing, considering the requirements of scenarios with extremely high sensitivity to communication reliability and latency, a probe density doubling strategy is adopted. Multiple probe devices are deployed around key nodes to form an array structure to achieve redundant coverage of probe signals, ensuring the accuracy and stability of communication link status awareness. In mMTC slicing, for scenarios with a large number of devices, a cluster polling mechanism is adopted. Several probes form a polling mode to alternately complete the monitoring tasks of device nodes within the slice, effectively reducing the resource overhead of network probing. In ordinary slice areas, a conventional probe density is used to balance network monitoring performance and resource consumption.
[0048] The probe device of the present invention specifically includes an active detection module, a passive traffic monitoring module, a data fusion and analysis unit, and a detection control module. The active detection module comprises a periodic detection unit and a designated detection unit; the periodic detection unit performs periodic detection based on the detection value priority of network nodes, while the designated detection unit can be configured by the detection control module to detect specific nodes or paths in real time according to changes in network status, in order to accurately address the monitoring needs of network anomalies or critical paths.
[0049] The passive traffic monitoring module includes a deep packet inspection unit and a traffic fingerprinting unit, which can obtain the link status and business anomalies in real time by deeply analyzing the business traffic passing through the nodes.
[0050] The data fusion and analysis unit receives probe data from the active detection module and the passive traffic monitoring module, and performs unified data aggregation through the data acquisition submodule. Then, it performs spatiotemporal mapping fusion through the data fusion submodule, and finally generates a dynamic routing state map based on network devices as nodes, communication links as edges, and state attributes as weights, providing intuitive and accurate decision support for network operation and maintenance and monitoring.
[0051] The detection control module includes a reinforcement learning-based decision-making unit and a detection mode switching control unit. The reinforcement learning decision-making unit dynamically optimizes the detection strategy and adjusts the activation and configuration of active detection, passive listening, or active-passive coordination modes by analyzing the current overall network load, the probability of abnormal events, the resource consumption ratio, and historical detection performance indicators.
[0052] In addition, the present invention also has the function of dynamic migration of probe nodes. When abnormal events such as base station switching or link rerouting occur in the network, the detection control module will quickly dispatch the probe device to migrate to the critical path in order to keep track of network status changes in real time and ensure the continuity and effectiveness of network monitoring.
[0053] like Figure 3 The diagram shown is a schematic representation of the specific workflow of the active detection module in the distributed network probe collaborative monitoring method of this invention.
[0054] In the network detection system of this embodiment, the active detection module plays a crucial role in real-time and proactively sensing changes in network status. Especially in 5G / 6G network environments, where network structures are more complex and service requirements are more diverse, the reliability and real-time performance of network links become paramount. To address these needs, this invention designs a flexible and efficient active detection module capable of performing detection in both periodic and targeted modes, achieving accurate perception and timely feedback of network link status.
[0055] First, regarding the periodic detection mode of the active detection module, the specific implementation method is as follows:
[0056] The core mechanism of the periodic probe mode is the periodic triggering of a probe interval timer. The specific duration of this timer is not a fixed value, but dynamically adjusted based on the number of neighboring nodes of the node containing the probe. Specifically, the probe interval of this node is inversely proportional to the number of its neighboring nodes. The specific formula for calculating the probe interval is as follows:
[0057]
[0058] in, The interval represents the duration of the probe, and N represents the total number of current neighboring nodes of this node. The system presets an inverse proportional adjustment coefficient for the detection interval. This dynamically adjusted detection interval design effectively avoids the problem of excessive detection load caused by an excessive number of network nodes, enabling the system to achieve a better dynamic balance between detection coverage and resource consumption.
[0059] When the timer triggers the detection, the active detection module does not simply select a detection target randomly, but first calculates the detection priority of neighboring nodes, thereby realizing intelligent selection of detection targets.
[0060] In some instances, each probe node maintains a neighbor node probe value table. This table records detailed information about the corresponding node, including each neighbor node's unique identifier (node ID), the absolute timestamp of the last probe, the current probe value, a probe timeout counter, and a probe anomaly counter. The probe value reflects the importance and priority of the neighbor node since its last probe. The probe value changes dynamically over time; even if a node is not probed, its probe value increases over time to ensure that all nodes have a chance to be probed and to avoid monitoring blind spots caused by prolonged periods of inactivity.
[0061] In some instances, the update rule for probe value is as follows: for every probe interval during which a node has not been probed, the probe value of that node automatically increases by a fixed increment (Inter), and the maximum probe value does not exceed a preset value (10). The dynamic update formula for probe value is shown below:
[0062]
[0063] in, The detection value before this neighboring node. This update strategy enhances the detection value of nodes that have not been detected for a long time, ensuring that node status can be detected in a timely manner.
[0064] To accurately determine the specific target node for each probe, this invention defines a formula for calculating probe priority:
[0065]
[0066] in, This represents the current detection value of the neighboring node in the table. It is the current timestamp. It is the timestamp of the last time this neighboring node was probed, recorded in the table. It is a unit conversion parameter that controls both conversion time and detection value. Lu is the upper bound of the detection value, and Lu is the link utilization of the port corresponding to the neighbor node.
[0067] The detection module calculates the detection priority of each neighboring node and selects the highest priority node for detection, thereby achieving efficient detection and ensuring that the link status of key nodes is monitored first.
[0068] During the actual probe operation, this node actively sends probe data packets to selected neighbor nodes and starts a probe timeout timer. If the probe data packet returns normally, the probe value is updated to 0, and the probe anomaly count of the corresponding node is reduced by 1 (if it is not 0). Conversely, if the probe data packet does not return in time, and the value of the probe timeout counter exceeds a predetermined threshold, the probe anomaly count of the node is increased by 1, while the probe value remains unchanged.
[0069] When the detection anomaly count reaches the threshold set by the system, the active detection module actively reports the abnormal status of the neighboring node to the detection control module and forcibly resets the detection value of the node to 0, so as to avoid abnormal nodes frequently occupying detection resources.
[0070] In some instances, the active probing module is also specifically designed with a designated probing mode. This mode is typically triggered directly by the probing control module to proactively sense or verify the link status of a specific path or certain key nodes in the network. Especially when used in conjunction with the passive traffic monitoring module, this probing mode can more accurately locate abnormal links or node problems, compensating for the inability of periodic probing to promptly address specific needs.
[0071] Once the designated detection mode is activated, the detection control module issues explicit instructions to the active detection module, specifying the detection path or target node. At this time, the active detection module directly sends detection data packets to nodes along the specified path and waits in real time for the return data packets, promptly determining if timeouts or link anomalies have occurred. It then quickly feeds back the detection results to the data fusion and analysis unit, which integrates the data collected by the passive monitoring module for a deeper and more comprehensive analysis of the network status, achieving the best synergy between active detection and passive monitoring.
[0072] The active detection module proposed in this embodiment is based on a periodic detection mode and supplemented by a designated detection mode. Through real-time intelligent analysis and priority calculation of the detection value of neighboring nodes and link status, it significantly improves the network detection accuracy, minimizes the waste of detection resources, and fully ensures the timeliness, accuracy and efficiency of 5G / 6G network status perception tasks.
[0073] In an embodiment of this invention, to achieve efficient and refined perception of link state anomalies in large-scale distributed networks, a passive monitoring-based anomaly detection and source tracing analysis method is proposed. This method passively acquires network traffic information and combines graph neural networks (GNNs) and Bayesian inference models to identify, trace, and analyze the root causes of abnormal paths. The process is as follows: Figure 4 The diagram shown is a flowchart of anomaly detection and source tracing analysis based on passive listening in an embodiment of the present invention.
[0074] like Figure 4As shown, the entire analysis process can be divided into five main stages, namely, the acquisition of input traffic data in the network environment, passive monitoring and processing, passive analysis engine, anomaly identification and root cause reasoning module output, and collaborative control feedback module.
[0075] After deployment, the distributed network probing system operates in a real communication network environment, as shown in the "Network Environment" module. The system continuously receives real-time traffic flow information from various terminal nodes, switching devices, or link boundaries, forming "input traffic data." This data includes network flow records, protocol metadata (TCP connection status, HTTP headers), and low-level characteristics of raw data packets such as size distribution, interval characteristics, and traffic peaks. This input data serves as the direct analysis object for the passive probing module.
[0076] In this embodiment, the input traffic data enters the "passive traffic monitoring module," which mainly consists of a deep packet inspection (DPI) unit and a traffic fingerprinting unit. The DPI unit performs multi-layered parsing of data packets from the transport layer to the application layer, extracting protocol behavior patterns and nested data content. The traffic fingerprinting unit quickly identifies specific types of communication behavior (P2P, DNS tunneling, scanning streams, etc.) using pre-trained feature templates, providing labeled suspicious traffic data for subsequent modules.
[0077] The data after the initial identification and labeling will be input into the "passive analysis engine framework". This framework is further subdivided into two major sub-modules: "anomaly source tracing analysis module" and "fault reasoning and location path module", which will execute abnormal behavior modeling and root cause location analysis in parallel.
[0078] In the "Anomaly Source Analysis Module," a network topology map is first constructed. Using probe nodes as observation points, the system integrates multi-node monitoring data to establish a communication graph model with network devices as nodes and links as edges. The edge weights in the graph are composed of indicators such as link latency, packet loss rate, and bandwidth utilization. Based on this, the system performs spatiotemporal correlation analysis on the topology map using a time sliding window mechanism to identify anomalous features such as sudden changes in connection behavior within a short period, abnormal path expansion, and lateral movement flows. Subsequently, the system uses a graph neural network (GNN) model to learn the state embeddings of nodes and edges, extracting their state distribution within the current time window. Based on abnormal traffic intensity, it predicts suspicious path directions, ultimately outputting "anomaly path tracing" results, including potential attack links, suspicious source nodes, and their upstream and downstream node sets.
[0079] Meanwhile, the "Fault Reasoning and Path Location Module" uses the constructed network topology to abstract each node or link into a random variable in a Bayesian network through mapping. First, it sets the prior probability of each node, reflecting its historical fault tendency. Then, it defines a conditional probability matrix based on topological connectivity, reflecting the strength of the impact of a node's anomaly on downstream links. The system uses a message-passing algorithm to perform joint reasoning on the entire Bayesian graph, and through multi-point data cross-validation, it derives the most likely path and node combination for faults. Finally, it outputs a "Root Cause Ranking List," arranging suspicious nodes and links according to their fault probability from high to low, to assist network maintenance personnel in quickly locating the source of the problem.
[0080] The results from the two modules mentioned above will be jointly fed into the "Result Collaborative Output Module," which is responsible for integrating the analysis results and generating instructions. The output mainly includes: First, based on the graph neural network model and Bayesian inference results, suspicious paths are marked on the graph, highlighting links with potential anomalies or faults; Second, based on the current monitoring coverage and anomaly concentration distribution, "Deployment Suggestions for Additional Probes" are automatically generated, recommending users to add relay probes, lightweight listeners, etc., at upstream and downstream nodes of the anomaly path to enhance the ability to distinguish abnormal behavior; Third, the system feeds back the complete anomaly marking map, root cause ranking list, and probe deployment suggestions to the detection control module, participating in the decision-making process for the next round of detection strategy optimization and switching between active / passive collaborative mechanisms.
[0081] Figure 4 The flowchart shown fully describes the anomaly detection and fault analysis mechanism based on passive traffic monitoring in this invention. By organically integrating deep packet inspection, graph neural network behavior modeling, and Bayesian network causal reasoning, high-precision anomaly path identification and problem source localization are achieved while ensuring controllable monitoring overhead, providing crucial intelligent analysis and feedback support for distributed network probe systems.
[0082] In embodiments of the present invention, such as Figure 5 As shown, the distributed network probe system relies on core components such as the "data fusion and analysis unit", "network state graph generation module" and "probe control module" to realize multi-source data aggregation, state graph construction and intelligent policy control based on reinforcement learning.
[0083] In the data fusion and analysis unit of this embodiment, heterogeneous data output by the active detection module and the passive monitoring module are uniformly collected and processed. The active detection module mainly provides link performance indicators, including latency, packet loss rate, and path reachability; the passive monitoring module extracts statistical information such as service flow characteristics, protocol behavior, and traffic mutations. These data are synchronized and unified through the spatiotemporal alignment module to ensure temporal consistency of information from different sources during the analysis phase.
[0084] The fused data is projected onto the logical network topology through a spatial mapping module, enabling the state information of different nodes and links to be expressed in a unified model. To ensure data accuracy and completeness, the fusion analysis unit also includes a data quality verification module, used to remove redundant and abnormal data, fill in missing values, and perform consistency checks. After these processes, the system obtains a unified state description vector that can be used for graph generation.
[0085] The state vector is then fed into the network state graph generation module to construct a visual representation of the network's operational status. In this embodiment, the graph module is designed with a multi-index layer structure, supporting the generation of the following network state layers: link health graph, path latency heatmap, bandwidth utilization distribution graph, and anomaly risk intensity graph, etc. Each layer is overlaid and rendered based on the topology graph structure to form a network state graph containing spatial structure and multi-dimensional states for use by the control module.
[0086] In the control strategy stage, this invention proposes an intelligent scheduling mechanism based on deep reinforcement learning to dynamically select active detection and passive listening modes, and adjust the detection frequency, path, and node deployment scheme accordingly. Specifically, the active / passive switching is modeled as a Markov decision process (MDP), and the state space is defined as:
[0087]
[0088] in, This represents the current overall network load (such as link utilization). This represents the predicted probability of abnormal events in the current network state obtained from passive monitoring data analysis (such as the probability of abnormal events output by an anomaly detection algorithm). This indicates the percentage of traffic generated by the active detection mode in the previous period; while This indicates the monitoring mode used in the previous moment, used to characterize the memory features in the decision-making process.
[0089] Regarding the definition of the action space, a reinforcement learning agent needs to choose between active exploration and passive monitoring modes at each decision-making moment. The action space is defined as follows:
[0090]
[0091] To ensure that the agent's decision-making is reasonable and effective, this study further clarifies the constraints on action selection: when the agent decides to adopt the active probing mode, it will activate the periodic probing flow of the network; while when the passive monitoring mode is selected, it only analyzes the existing traffic statistics and does not generate additional network traffic overhead.
[0092] The core of reinforcement learning decision-making lies in the design of the reward function. This study designs a reward function that considers detection accuracy, resource overhead, and state switching penalties to drive the agent to balance detection performance with bandwidth consumption. Specifically, it is defined as follows:
[0093]
[0094] in, This represents the detection effectiveness index, which is the accuracy rate of active detection in identifying abnormal events at the current moment (if it is a passive monitoring mode, this item is the accuracy rate of abnormal event prediction). This represents the additional bandwidth consumption caused by active probing, defined as the ratio of probing traffic to total network traffic (this value is 0 for passive monitoring). The mode switching cost term is defined as follows:
[0095]
[0096] Weighting coefficients in the reward function , , These are used to adjust the trade-offs between detection accuracy, detection overhead, and mode switching costs, respectively, in order to dynamically adapt to the management needs of different network scenarios.
[0097] Furthermore, this study employs a deep reinforcement learning algorithm (Deep Q-Network, DQN) to solve the aforementioned MDP model, using a deep neural network to approximate the action-value function. The parameters are Specifically, the update of the action-value function follows the Bellman optimality equation:
[0098]
[0099] in, For learning rate, ∈(0,1) is a discount factor used to balance the relationship between immediate rewards and long-term rewards. These are the target network parameters, used to improve the stability of algorithm training. The parameters are adjusted every fixed number of steps from the current parameters. Copy and update once.
[0100] To enhance decision stability and generalization performance during training, an experience replay mechanism is introduced. This mechanism is implemented in the experience replay pool. In the middle, experience tuples that store historical decisions The agent updates network parameters by randomly sampling small batches of experience, and the loss function is defined as the mean squared error between the predicted action value and the actual action value.
[0101]
[0102] The policy function of the agent after training and optimization is defined as follows:
[0103]
[0104] In actual operation, the agent observes the network state in real time and applies the optimal strategy obtained during training. Select the monitoring mode that is suitable for the current network status, so as to proactively reduce the overhead of probe traffic when the network load is light and the status is stable, and switch to active probe mode in time when the risk of anomalies increases or the network status is highly uncertain, so as to accurately capture network anomalies and deal with them in a timely manner.
[0105] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the marine satellite Internet of Things blockchain sharding method.
[0106] Corresponding to the above method, the present invention also provides an apparatus comprising a computer device, the computer device including a processor and a memory, the memory storing computer instructions, the processor executing the computer instructions stored in the memory, and when the computer instructions are executed by the processor, the apparatus performs the steps of the method as described above.
[0107] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the aforementioned edge computing server deployment method. The computer-readable storage medium can be a tangible storage medium, such as random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, floppy disks, hard disks, removable storage disks, CD-ROMs, or any other form of storage medium known in the art.
[0108] In summary, this invention provides a route status awareness method and device for distributed network probe collaborative monitoring, applicable to 5G / 6G network environments. By combining the advantages of active detection and passive monitoring, it achieves efficient and low-overhead network status awareness. The method includes: deploying distributed probe devices at key nodes, integrating an active detection module, a passive traffic monitoring module, a data fusion analysis unit, and a detection control module; the active detection module supports periodic and targeted detection, dynamically adjusting detection priorities and paths; the passive monitoring module uses deep packet inspection and machine learning models to achieve fault location and anomaly tracing; the data fusion analysis unit constructs a dynamic route status graph using a spatiotemporal correlation algorithm to characterize link health and abnormal situations; the detection control module introduces a reinforcement learning model to dynamically switch detection modes based on network load, resource consumption, and historical indicators, balancing detection accuracy and overhead. This invention significantly improves network awareness accuracy and reduces resource consumption through active-passive collaborative detection and intelligent decision-making mechanisms, supporting efficient autonomous operation and maintenance of 5G / 6G networks.
[0109] Furthermore, this invention constructs a detection result expression mechanism based on anomaly annotation and visualization map, which supports multi-dimensional display of link status and explicit identification of abnormal behavior, improving the intuitiveness and operability of network situational awareness; it designs a configurable data output framework that is compatible with a variety of standardized interfaces and data formats, making it easy to integrate with existing network management systems and meet the needs of flexible adaptation and system scalability in complex network environments.
[0110] Those skilled in the art will understand that the exemplary components, systems, and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software, or a combination of both. Whether implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this invention. When implemented in hardware, it can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this invention are programs or code segments used to perform the desired tasks. The programs or code segments can be stored in a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried in a carrier wave.
[0111] It should be clarified that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of the present invention.
[0112] In this invention, features described and / or illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, and / or combined with or in place of features of other embodiments.
[0113] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, various modifications and variations of the embodiments of the present invention are possible. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method and apparatus for route status awareness through distributed network probe collaborative monitoring, characterized in that, Link status awareness in 5G / 6G network environments combines the advantages of active and passive detection to improve network awareness accuracy in a highly efficient and low-overhead manner, including the following steps: Step 1: Deploy distributed probe devices on multiple key nodes of the 5G / 6G network. The probe devices include an active detection module, a passive traffic monitoring module, a data fusion analysis unit that collects detection data, and a detection control module that executes detection strategy control. Step 2: The active detection module provides two detection triggering methods: one is periodic detection, which is triggered periodically by dynamically adjusting the frequency. When triggered, the target node is selected based on the calculated detection priority. Each node maintains a neighbor node detection value table to record the detection value of neighbor nodes; the other is designated detection, which detects specific nodes or paths by specifying a detection path, and is used for scheduling in combination with passive listening. Step 3: The passive traffic monitoring module monitors the service flow through deep packet inspection and traffic fingerprinting, performs fault location based on the improved Bayesian network fault reasoning model, and performs source tracing analysis based on the machine learning model. Step 4: The data fusion and analysis unit collects real-time data based on the network data analysis function of the 5G / 6G network. Through time alignment and spatial mapping algorithms, it spatiotemporally correlates the data of active detection and passive monitoring to generate a routing state map with network devices as nodes, communication links as edges, and state attributes as weights. Step 5: The detection control module introduces an intelligent decision-making model based on reinforcement learning to dynamically select between active detection, passive monitoring, and active-passive coordinated detection modes according to the current network state characteristics. The network state characteristics include overall link load, predicted probability of network anomalies, resource consumption ratio under the current mode, and historical detection performance indicators. Based on the optimal strategy generated by the reinforcement learning model, the detection control module senses the above states in real time and switches to the optimal detection method, achieving a dynamic balance between detection overhead and detection accuracy.
2. The route status awareness method for distributed network probe collaborative monitoring as described in claim 1, characterized in that, In step one, the deployment density of the distributed probe devices is dynamically adjusted according to the 5G / 6G network slice type, including: implementing a probe density doubling strategy for ultra-reliable low-latency communication slices; implementing a probe cluster polling mechanism for massive machine-type communication slices; and triggering probe migration to critical paths when base station switching or path rerouting is detected. The probe density doubling strategy specifically includes: establishing a slice criticality assessment model. ,in The probe density coefficient, The slice delay sensitivity level, To meet the bandwidth requirements of slicing, For dynamically adjusted parameters; based on real-time calculations The value is used to deploy probe relay arrays at the edge nodes of URLLC slices to form redundant probe signal coverage.
3. The route status awareness method for distributed network probe collaborative monitoring as described in claim 1, characterized in that, Step two describes an active detection module that maintains a neighbor node detection value table, recording the detection value of neighbor nodes. The processing rules for this neighbor node detection value table include: Each entry in the neighbor node detection value table corresponds to a neighbor node. Each entry stores a unique neighbor node ID and a timestamp of the absolute time when the node was last detected. The range of values is within The value of detection Detection timeout counter value and anomaly count with an initial value of 0 ; When this node probes a neighboring node and returns the probe result, it updates the probe timestamp of that neighboring node in the neighboring node probe value table to the time of the returned probe packet and updates the probe value to 0. Even if this node does not probe some nodes, the probe value entries in the neighbor node probe value table will be updated over time, increasing up to a maximum of 10. The update of the probe value satisfies the formula: , Inter is a fixed incrementing value representing the probe value of the neighboring node during the update. The periodic detection method of the active detection module described in step two selects the next hop based on the calculated detection priority. The specific detection and calculation rules are as follows: Each node independently maintains its own probe timer. The probe time interval of a node is inversely proportional to the number of neighboring nodes, i.e., it satisfies the formula: , is the detection interval, N is the number of neighboring nodes of this node, and C is a fixed inverse proportional adjustment parameter of the detection interval; This node triggers a probe at the beginning of each probe cycle, and the number of nodes probed each time is fixed. The detection priority of a neighboring node is calculated using the following formula: , This represents the current detection value of the neighboring node in the table. It is the current timestamp. It is the timestamp of the last time this neighbor node was probed, recorded in the table. It is a unit conversion parameter that controls both conversion time and detection value. Lu is the upper bound of the detection value, and Lu is the link utilization of the port corresponding to the neighbor node. After this node sends a probe message to a neighboring node, it maintains a probe timeout timer for that node to determine the probe status based on the probe return time. In this detection method, if the node detects that the timeout counter value for a certain node exceeds a certain threshold... Then, the timer will be turned off and cleared, and the detection anomaly count for that node will be reset. Increase by 1; at this point, since no detection result for that neighboring node has been returned, no update to the detection value will be performed; when the... The value reached the detection anomaly count threshold. When the abnormal condition of the neighboring node is reported to the detection control module, the detection value of the neighboring node is recorded as 0, and the abnormal condition of the neighboring node is recorded as 0. Recorded as 0; and when the probe returns a result, and at this time... If the value is not 0, then Decrease the value by 1.
4. The route state awareness method for distributed network probe collaborative monitoring as described in claim 1, characterized in that, Step 3 describes a passive traffic monitoring module that monitors service flows through deep packet inspection and traffic fingerprinting. It performs source tracing analysis based on a machine learning model. The mechanism includes: the system uses a machine learning-based anomaly tracing model to construct a full network topology map using graph neural networks and combines spatiotemporal data for source tracing inference; the model determines the flow direction of abnormal data packets by capturing dynamic changes in network status and establishes data associations between multiple probe points, thereby accurately tracing the source of malicious traffic; in anti-source tracing scenarios, when the detection system identifies a path that may involve malicious activity, it deploys additional probes at upstream and downstream nodes of that path to construct an adaptive detection network, accurately capturing abnormal paths with high spatial resolution. The passive traffic monitoring module described in step three monitors service flows through deep packet inspection and traffic fingerprinting, and performs fault location based on an improved Bayesian network fault reasoning model. The mechanism includes: mapping links and nodes in the network topology to random variables of a Bayesian network; setting prior fault probabilities for each variable based on historical reliability data; establishing a conditional probability relationship matrix between node faults and probe-observed symptoms; and implementing multi-evidence joint reasoning through a message passing algorithm to output the probability ranking of fault root causes.
5. The route state awareness method for distributed network probe collaborative monitoring as described in claim 1, characterized in that, The data fusion analysis unit in step four is implemented based on the network data analysis function of 5G / 6G networks, and the process includes: Data acquisition phase: The probe device continuously collects link connectivity information and probe response characteristics from the active detection module, as well as service traffic fingerprints, abnormal behavior records, and fault inference results from the passive monitoring module; Data fusion stage: Time alignment and spatial mapping algorithms are used to fuse heterogeneous data and construct a multi-dimensional topology state diagram that includes link health, abnormal heat, latency and bandwidth utilization. Routing state graph generation: Based on the above fused data, a dynamically evolving routing state graph is generated. In the graph, nodes represent network devices, edges represent communication links, and associated state attributes in the graph are used to characterize the network operation status. Policy feedback mechanism: The fusion analysis unit integrates the suggestion module based on the policy reasoning model, and combines the current map status and historical trends to output control suggestions and instructions for route path reconfiguration, slice resource adjustment or network anomaly warning; Visualization support: The map supports graphical display, including link utilization heatmaps, abnormal path highlighting, and topology change timelines, to assist maintenance personnel in making intelligent decisions.
6. The route state awareness method for distributed network probe collaborative monitoring as claimed in claim 1, characterized in that, The designated detection method of the active detection module described in step two is used in conjunction with passive monitoring. Further, the detection control module described in step five implements this by introducing an intelligent scheduling mechanism that integrates active detection and passive monitoring based on reinforcement learning. Specifically, this includes: The state space includes feature vectors that describe the current overall link load of the network, the current probability of abnormal events, the resource consumption ratio under the current mode, and historical detection performance indicators. The action space is defined as the dynamic selection of active detection mode, passive listening mode, and active-passive coordinated detection mode. In active detection mode, periodic or specified detection is activated. In passive listening mode, only existing traffic statistics are analyzed without generating additional network traffic. In active-passive coordinated detection mode, both active detection and passive listening are used. The reward function is designed by weighting the overall detection effect, network bandwidth resource consumption, and mode switching cost. The intelligent decision-making model obtains the optimal strategy through deep reinforcement learning algorithm training, perceives the network state in real time, and dynamically adjusts the detection mode according to the optimal strategy obtained from training. In this way, the detection frequency or range is reduced when the network state is stable, and the active detection frequency or detection range is increased in a timely manner when the network anomaly risk increases, so as to achieve a dynamic balance between detection overhead and detection accuracy.
7. A distributed network probe routing monitoring system, characterized in that, include: The probe device deployed at 5G / 6G network nodes includes an active probe packet generation module and a passive traffic acquisition module; The central control and analysis module includes: a probe task scheduling unit, used to dynamically configure the monitoring strategies of each probe; A multi-source data aggregation unit is used to align and store routing status data from active probing and passive monitoring; The intelligent analysis unit integrates machine learning models and a Bayesian inference engine to perform anomaly detection, fault prediction, and root cause analysis. The self-healing strategy execution unit triggers path switching, traffic engineering adjustment, and slice resource reallocation operations based on the analysis results. The system is configured to include the method of any one of claims 1 to 6 to achieve real-time perception and autonomous recovery of the routing status of 5G / 6G networks.
8. A routing device supporting distributed network probe collaborative monitoring, characterized in that, Includes the following hardware and functional modules: The probe deployment interface module provides a communication interface with the 5G / 6G network slice controller, receiving slice type and topology change commands; it supports software-defined programmable capabilities for deploying active probe modules and passive monitoring modules; and it may have a hardware acceleration module for traffic analysis and model deployment. It has a storage module for storing neighbor node detection value tables and passive listening temporary data; It has a communication module to support the software-defined network southbound interface, network slice management interface and probe collaborative communication protocol; The probe deployment interface module, active detection module, passive listening module, hardware acceleration module, storage module, and communication module are configured to collaboratively execute the steps of the method as described in any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Wireless network detection method suitable for high-speed mobile environment
CN108093430A
Data center load balancing method based on responsive probe and flow classification
CN118631742A