Network monitoring method and device and electronic equipment
By creating an IP address pool and dynamically updating the denoising status, the real-time and accuracy problems of network monitoring in large data centers are solved, and efficient network quality monitoring and fault location are achieved.
Patent Information
- Application Number
- CN202510498214.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-09-02
AI Technical Summary
The existing technology cannot achieve comprehensive, real-time and accurate network quality monitoring of large data center networks, and is costly and is prone to false alarms.
By creating an IP address pool, probing tasks are sent to multiple detection nodes, probing periodically performing detection based on the preset packet algorithm, dynamically update the denoising state of the IP address, performing detection tasks only on the active IP addresses, and aggregating the detection results and alerting them.
It realizes network quality monitoring of the entire scenario, high real-time and high accuracy of large data center networks, improves network fault detection and positioning efficiency, shortens the network fault duration, and reduces the occurrence of false alarms.
Smart Images

Figure CN120583008A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of network data analysis, and in particular to a network monitoring method, device, and electronic device. Background Art
[0002] IDC (Internet Data Center) networks are essential infrastructure capabilities for most projects to provide continuous and stable services. Network failures are inevitable and usually have a wide impact. How to quickly discover and locate network failures is crucial to ensuring network stability.
[0003] In related technologies, ping tests are performed regularly on a small number of IP addresses such as key network nodes and servers to determine whether the network is reachable and whether the network latency is normal. This can be achieved by using a simple ping program for a single IP address or an fping program for multiple IP addresses. However, this method can only cover part of the network communication path and cannot achieve comprehensive monitoring of large data center networks. Moreover, when the number of IP addresses increases, the performance consumption of simple ping or fping programs is large and the latency accuracy is low, which cannot support the monitoring of large data center networks. Summary of the Invention
[0004] The purpose of the present disclosure is to provide a network monitoring method, device and electronic device, which can realize full-scene, high-real-time and high-accuracy network quality monitoring of large data center networks in seconds at a low cost.
[0005] In a first aspect, the present disclosure provides a network monitoring method, which is applied to a central control device, and the central control device is communicatively connected to multiple detection nodes. The method includes: creating an IP address pool, the IP address pool including multiple IP addresses to be detected; creating multiple detection tasks based on the IP address pool; wherein the detection task is bound to at least one IP address in the IP address pool; issuing multiple detection tasks to multiple detection nodes respectively, so that the multiple detection nodes periodically execute the detection tasks based on a preset packet receiving and sending algorithm, obtain detection result data, and report the detection result data to the central control device; wherein the detection result data includes at least the packet loss rate and / or delay of the IP address corresponding to the detection task; based on the detection result data, dynamically updating the denoising status corresponding to the IP address in the IP address pool, and synchronizing the denoising status corresponding to the IP address to the detection node; wherein the detection node only executes the detection task for the IP address whose denoising status is active; aggregating the detection result data to obtain the aggregated detection result, storing the aggregated detection result and performing network monitoring alarm based on the aggregated detection result.
[0006] In a second aspect, the present disclosure provides a network monitoring device, which is arranged in a central control device, and the central control device is communicatively connected to multiple detection nodes. The device includes: an address pool creation module, which is used to create an IP address pool, and the IP address pool includes multiple IP addresses to be detected; a task creation module, which is used to create multiple detection tasks based on the IP address pool; wherein the detection task is bound to at least one IP address in the IP address pool; a task issuing module, which is used to issue multiple detection tasks to multiple detection nodes respectively, so that the multiple detection nodes periodically execute the detection tasks based on a preset packet receiving and sending algorithm, obtain detection result data, and report the detection result data to the central control device; wherein the detection result data at least includes the packet loss rate and / or delay of the IP address corresponding to the detection task; a status update module, which is used to dynamically update the denoising status corresponding to the IP address in the IP address pool based on the detection result data, and synchronize the denoising status corresponding to the IP address to the detection node; wherein the detection node only executes the detection task for the IP address whose denoising status is active; a data aggregation module, which is used to aggregate the detection result data to obtain the aggregated detection result, store the aggregated detection result and perform network monitoring alarm based on the aggregated detection result.
[0007] In a third aspect, the present disclosure provides an electronic device, which includes a processor and a memory, wherein the memory stores machine-executable instructions that can be executed by the processor, and the processor executes the machine-executable instructions to implement the above-mentioned network monitoring method.
[0008] In a fourth aspect, the present disclosure provides a computer-readable storage medium storing computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions prompt the processor to implement the above-mentioned network monitoring method.
[0009] The embodiments of the present disclosure bring the following beneficial effects:
[0010] The present disclosure provides a network monitoring method, device and electronic device, which first create an IP address pool, which includes multiple IP addresses to be detected; create multiple detection tasks based on the IP address pool, and the detection task is bound to at least one IP address in the IP address pool; then issue multiple detection tasks to multiple detection nodes respectively, so that the multiple detection nodes periodically execute the detection tasks based on a preset packet receiving and sending algorithm, obtain detection result data, and report the detection result data to a central control device; wherein the detection result data at least includes the packet loss rate and / or delay of the IP address corresponding to the detection task; then, based on the detection result data, dynamically update the denoising status corresponding to the IP address in the IP address pool, and synchronize the denoising status corresponding to the IP address to the detection node; wherein the detection node only executes the detection task for the IP address whose denoising status is active; aggregate the detection result data to obtain aggregated detection results, store the aggregated detection results, and perform network monitoring alarms based on the aggregated detection results. This method allows users to flexibly configure network link detection tasks and automatically update the address pool of the detection tasks, realizing network link quality monitoring in all business scenarios, improving the efficiency of network fault discovery and location, shortening the duration of network faults, and reducing the impact of network faults.
[0011] Other features and advantages of the present disclosure will be set forth in the following description, or some features and advantages may be inferred or unambiguously determined from the description, or may be learned by practicing the above-mentioned technology of the present disclosure.
[0012] In order to make the above-mentioned objects, features and advantages of the present disclosure more obvious and easy to understand, preferred embodiments are specifically listed below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the specific embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0014] Figure 1 A flowchart of a network monitoring method provided by an embodiment of the present disclosure;
[0015] Figure 2 A schematic diagram of transitions between various denoising states provided in an embodiment of the present disclosure;
[0016] Figure 3 A schematic diagram of a dynamic address pool denoising method provided in an embodiment of the present disclosure;
[0017] Figure 4A flowchart of a preset packet sending and receiving algorithm provided in an embodiment of the present disclosure;
[0018] Figure 5 An overall architecture diagram of a network monitoring system provided by an embodiment of the present disclosure;
[0019] Figure 6 This is an overall architecture diagram of a central control layer provided in an embodiment of the present disclosure;
[0020] Figure 7 An overall architecture diagram of a detection layer provided in an embodiment of the present disclosure;
[0021] Figure 8 A schematic diagram of the structure of a network monitoring method provided by an embodiment of the present disclosure;
[0022] Figure 9 A schematic structural diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure more clear, the technical solutions of the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present disclosure. Obviously, the described embodiments are only some of the embodiments of the present disclosure, but not all of them. Generally, the components of the embodiments of the present disclosure described and shown in the drawings herein can be arranged and designed in various different configurations.
[0024] Therefore, the following detailed description of the embodiments of the present disclosure provided in the accompanying drawings is not intended to limit the scope of the present disclosure as claimed, but merely represents selected embodiments of the present disclosure. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present disclosure without creative effort shall fall within the scope of protection of the present disclosure.
[0025] An IDC provides server hosting, space rental, and network bandwidth services to ICPs (Internet Content Providers) and enterprises, enabling centralized data processing, storage, and management. IDC networks are essential infrastructure for delivering continuous and stable services in most projects. Network failures are inevitable and often have widespread and impactful consequences. Therefore, quickly identifying and locating network failures is crucial for ensuring network stability.
[0026] Currently, the main solutions for network link quality monitoring are:
[0027] The first solution involves monitoring network device status (such as interface traffic, CPU utilization, and memory usage) to identify network failures or performance issues. For example, this approach can detect device anomalies based on the device's RSYSLOG logs or collect network device status using the SNMP protocol. However, this approach cannot simulate actual business data traffic and cannot cover all business network communication scenarios.
[0028] The second approach involves periodically pinging a small number of IP addresses, such as those for key network nodes and servers, to determine network reachability and latency. This can be accomplished using a simple ping program for a single IP address or an fping program for multiple IP addresses. However, this approach only covers a portion of the network communication path and cannot provide comprehensive monitoring for large data center networks. Furthermore, using simple ping or fping programs increases performance overhead and reduces latency accuracy as the number of IP addresses increases, making them unsuitable for monitoring large data center networks.
[0029] The second solution is to have all servers in the data center periodically select other servers for ping tests (the Fullmesh solution). This solution requires the installation of monitoring programs on all servers. Because it cannot consume too much business performance, each server needs to select a small number of target nodes according to certain rules for ping tests. The ping test results are then aggregated and monitored for alarms. However, this method requires the installation of monitoring programs on all servers, sacrificing some business performance and resulting in high costs. Moreover, the IP selection rules rely on the stability of the server status and the consistency of the network architecture. When encountering diverse business types and complex network architectures, effective monitoring cannot be achieved, and false alarms are prone to occur.
[0030] In related technologies, ping tests are performed regularly on a small number of IP addresses such as key network nodes and servers to determine whether the network is reachable and whether the network latency is normal. This can be achieved by using a simple ping program for a single IP address or an fping program for multiple IP addresses. However, this method can only cover part of the network communication path and cannot achieve comprehensive monitoring of large data center networks. Moreover, when the number of IP addresses increases, the performance consumption of simple ping or fping programs is large and the latency accuracy is low, which cannot support the monitoring of large data center networks.
[0031] Therefore, it is necessary to conduct comprehensive and effective monitoring of network link quality. The above solutions cannot cover all scenarios, cannot support large-scale data center network monitoring, and are prone to false alarms. A solution is needed to achieve full-scenario, high-real-time, and high-accuracy network quality monitoring in seconds for large-scale data center networks at a lower cost.
[0032] Based on the above problems, the embodiments of the present disclosure provide a network monitoring method, device and electronic device. This technology can be applied to scenarios such as data center-to-data center (DCI), data center-to-data center (DCN), operator public network exit, SNAT gateway, public cloud, network device activity detection, etc.
[0033] In order to facilitate understanding of the embodiments of the present disclosure, a network monitoring method disclosed in the embodiments of the present disclosure is first described in detail. The method is applied to a central control device, which is connected to multiple detection nodes in communication, such as Figure 1 As shown, the method includes the following specific steps:
[0034] Step S102: Create an IP address pool, where the IP address pool includes multiple IP addresses to be detected.
[0035] In specific implementations, the IP addresses to be tested can be obtained from Excel spreadsheets uploaded by users, automatically generated from the server resource management system, or automatically generated from the public IP address database. Some sources support providing IP addresses in the form of IP segments. For IP segment formats, you can specify certain detection nodes to perform exhaustive IP enumeration for real-time detection tasks, periodically screening for IP addresses available on all nodes. The obtained IP addresses and custom tags are then combined into an address list, which becomes the IP address pool.
[0036] The IP address pool is an address list consisting of multiple IP addresses and a custom label. The custom label is used to indicate the computer room code and network type corresponding to the IP address. Table 1 shows an instantiation of the IP address pool. For example, the computer room code corresponding to the IP address 10.1.1.1 in Table 1 is XXX01, and the corresponding network type is intranet. The computer room code corresponding to the IP address 11.0.0.2 in Table 1 is XXX02, and the corresponding network type is extranet. Subsequent detection result data will carry the custom label corresponding to the IP address, making it easier to aggregate the detection data.
[0037] Table 1
[0038] IP address Computer room code Network Type 10.1.1.1 XXX01 Intranet 11.0.0.2 XXX02 Extranet ...... ...... ......
[0039] In practice, the central control device includes a centralized scheduler responsible for centrally managing address pools, detection tasks, and detection nodes, as well as providing data aggregation and query capabilities. Users can customize configurations through the front-end user interface provided by the central control device. Specifically, the detection nodes and the central control device can use gRPC two-way communication. Each detection node uses a small number of servers to perform detection tasks for large quantities of IP addresses. The central control device includes an address pool management module that can manage multiple IP address pools.
[0040] Step S104: creating multiple detection tasks based on the IP address pool; wherein the detection task is bound to at least one IP address in the IP address pool.
[0041] After creating an IP address pool, you can create a detection task. A single detection task can be bound to multiple IP address pools. For example, an IDC public network egress monitoring task (equivalent to the detection task described above) specifies both a detection public network IP address pool and an edge node data center external network IP address pool. After binding a detection task to an IP address pool, you also need to bind the detection task to a detection node. This specifies the detection node that will execute a specific detection task. For example, an IDC public network egress monitoring task can specify multiple detection nodes in IDC data centers across multiple regions.
[0042] During implementation, you'll need to specify a timing period for each probe task, for example, executing a probe task every 10 seconds. Additionally, each probe task includes adjustable parameters, such as the ping timeout, ping packet size, number of packets sent per probe, packet sending interval, and source IP address. You can also set a time range for each task.
[0043] In an optional embodiment, real-time denoising related parameters can also be set for the detection task: the IP addresses in the address pool can be grouped according to certain target tags (need to be selected according to the specific monitoring scenario, generally there is a clustering in spatial location, such as the network detection tasks in the computer room are grouped by computer room, and the public network detection tasks are grouped by province), and the number of IPs expected to be detected in a group and the minimum number that needs to be met can be specified.
[0044] In step S106, multiple detection tasks are respectively issued to multiple detection nodes, so that the multiple detection nodes periodically execute the detection tasks based on the preset packet receiving and sending algorithm, obtain the detection result data, and report the detection result data to the central control device; wherein the detection result data at least includes the packet loss rate and / or delay of the IP address corresponding to the detection task.
[0045] After creating a detection task, you need to send the detection task to multiple detection nodes. A detection node can execute one or more detection tasks, and each detection task corresponds to a different IP address.
[0046] The above-mentioned preset packet sending and receiving algorithm can be determined according to R&D needs. The preset packet sending and receiving algorithm is a high-performance and high-precision packet sending and receiving algorithm that performs the detection of large quantities of IP addresses in the detection task. The detection result data can include source label, destination IP label, packet loss rate, delay, etc.
[0047] Step S108, based on the detection result data, dynamically update the denoising status corresponding to the IP address in the IP address pool, and synchronize the denoising status corresponding to the IP address to the detection node; wherein, the detection node only performs the detection task for the IP address whose denoising status is active.
[0048] During the detection process, since the server where the IP address is located may be shut down and restarted or the IP address may be changed, the detected IP address will become invalid, and noisy data will appear in the detection result, affecting the accuracy and real-time performance of the alarm (because the alarm rule needs to set a higher threshold to avoid false alarms, so it affects the real-time performance). To solve this problem, ideally, it is necessary to predict the invalid IP address in advance, update the address pool corresponding to the detection task before the failure, and remove the invalid IP address. However, since the server may be restarted unexpectedly and the server status cannot be known for the public IP, it is not possible to predict in advance. In order to eliminate noise data at the source as much as possible, the present disclosure provides a method for dynamically updating the denoising status corresponding to the IP address in the IP address pool based on the detection result data. This method can denoise the address pool in real time in the central control device, thereby avoiding the detection node from performing detection tasks on invalid IP addresses and improving the accuracy of the detection data.
[0049] In specific implementation, if all detection nodes in the detection result data indicate that the detection result corresponding to a certain IP address is abnormal, the denoising state corresponding to the IP address in the IP address pool will be initially adjusted to an abnormal state. The IP address in the abnormal state is equivalent to the above-mentioned invalid IP address.
[0050] Step S110 , performing aggregation processing on the detection result data to obtain an aggregated detection result, storing the aggregated detection result, and performing network monitoring alarm based on the aggregated detection result.
[0051] In the specific implementation, the detection node can perform the detection task at a customizable period (generally within 10 seconds), and report the detection result data to the central control device so that the central control device can aggregate the detection result data corresponding to each detection node received, and store the aggregated detection results in the time series database, and push them to the monitoring alarm service to generate an alarm.
[0052] The above-mentioned aggregation processing can be understood as grouping the data by certain columns and taking the maximum value, minimum value or average value of the data in each group.
[0053] A network monitoring method provided by an embodiment of the present disclosure supports users to flexibly configure network link detection tasks and automatically update the address pool of the detection tasks, thereby realizing network link quality monitoring in all business scenarios, improving the efficiency of network fault detection and positioning, shortening the duration of network faults, and reducing the impact of network faults.
[0054] The following embodiments are used to describe the method of address pool denoising.
[0055] Specifically, after creating multiple detection tasks based on the IP address pool, it is necessary to maintain a denoising status belonging to the corresponding detection task for each IP address bound to the detection task; wherein the denoising status is used to indicate whether the IP address is currently abnormal.
[0056] After the detection task is created, the task management module will maintain a denoising status belonging to the detection task for each IP address in the address pool bound to the detection task. The address pool that records the denoising status is the dynamic address pool of the detection task. The denoising status classification is shown in Table 2. For tasks that require real-time denoising function, the system automatically switches between several real-time denoising states. For special scenarios, users can specify the status, such as specifying fixed detection of certain IP addresses or disabling certain IP addresses.
[0057] Table 2
[0058]
[0059] Based on the above description, after issuing multiple detection tasks to multiple detection nodes respectively, the following operations are performed for each detection task: the denoising status corresponding to the specified number of IP addresses bound to the detection task is set to the active state, and the denoising status corresponding to the IP addresses other than the active state among the IP addresses bound to the detection task is set to the normal state, so that the detection node performs the detection task on the IP address in the active state and obtains the detection result data.
[0060] In specific implementations, the active state is also the active state, and the normal state is also the healthy state. The specified number is also the number of IP addresses expected to be detected in the denoising-related parameters. The specific number corresponding to the specified number can be determined based on R&D requirements.
[0061] like Figure 2The figure shows a transition diagram between various denoising states. For detection tasks requiring real-time denoising, the IP addresses in the dynamic address pool are initially grouped according to the specified grouping label. The desired number of IP addresses in each group are selected and transitioned to the active state, while the remaining IP addresses remain in the healthy state. After the detection task is issued, the detection node performs the detection task on the IP addresses in the active state. During the task execution, if a noisy IP address (that is, an invalid IP address) is found, denoising replacement is performed, and the active state is transitioned to the unhealthy state (equivalent to an abnormal state). At the same time, the healthy IP addresses in the group are selected and transitioned to the active state. In addition, the central control device periodically initiates real-time health check tasks to perform health checks on IP addresses in both healthy and unhealthy states. IP addresses with normal check results can be restored from the unhealthy state to the healthy state, while abnormal IP addresses are invalidated from the healthy state to the unhealthy state.
[0062] Based on this, the specific process of dynamically updating the denoising status corresponding to the IP addresses in the IP address pool based on the detection result data includes: if the detection result data corresponding to the first IP address in the active state is abnormal, determine whether there is an IP address with a normal denoising status among the IP addresses bound to the detection task; if so, adjust the denoising status corresponding to the first IP address to an abnormal state, and select a second IP address from the IP addresses in the normal state among the IP addresses bound to the detection task, and adjust the denoising status corresponding to the second IP address to an active state.
[0063] In specific implementation, the number of the above-mentioned second IP addresses is the same as the number of the first IP addresses, or the number of the second IP addresses meets the first quantity requirement. The specific value corresponding to the first quantity requirement can be determined according to R&D needs, and the first quantity requirement can also be the above-mentioned specified number.
[0064] Furthermore, if the detection result data corresponding to the first IP address in the active state is abnormal, determine whether there is an IP address with a normal denoising state among the IP addresses bound to the detection task; if there is no IP address with a normal denoising state among the IP addresses bound to the detection task, determine whether the IP addresses in the active state among the IP addresses bound to the detection task meet the second quantity requirement if the denoising state corresponding to the first IP address is adjusted to an abnormal state; if so, adjust the denoising state corresponding to the first IP address to an abnormal state; if not, keep the denoising state corresponding to the first IP address as active.
[0065] In specific implementation, the specific value corresponding to the above-mentioned second quantity requirement can be determined according to research and development needs. For example, the second quantity requirement is the minimum quantity that needs to be met set in the denoising-related parameters.
[0066] Furthermore, the specific process of aggregating the detection result data to obtain the aggregated detection result may further include: if the denoising state corresponding to the first IP address is adjusted to an abnormal state, deleting the detection result data corresponding to the first IP address in the detection result data to obtain updated detection result data; and aggregating the updated detection result data to obtain the aggregated detection result. This approach helps improve the accuracy of the detection results.
[0067] like Figure 3 The figure shows a schematic diagram of a dynamic address pool denoising provided by an embodiment of the present disclosure. When a detection task starts, the dynamic address pool state of the task is initialized according to the denoising related parameters (grouping label, expected number of each group, minimum number of each group) configured by the user: first, the address pool IP is grouped according to the grouping label, Figure 3 The example uses the room code to group, (ip1, ip2) as one group, ip3 as another group; each group selects the desired number of IPs to be initialized to the active state, and the other IPs are initially in the healthy state. Figure 3 In this example, the expected number of groups is 1, the minimum number of groups is 1, and (ip1, ip3) is selected. The detection task is then sent to the detection layer. Each detection node in the detection layer performs periodic detection tasks (for example, every 10 seconds), detecting active IP addresses in the dynamic address pool and reporting the detection results to the central control layer (equivalent to the central control device mentioned above). The central control layer's data aggregation module summarizes the detection results of each detection node in a cycle. Because the timers of each detection node and the duration of the task execution are not completely consistent, the central control layer needs to wait for a certain period of time, but it will not exceed one task cycle.
[0068] Figure 3 The process of abnormal data identification and dynamic address pool denoising update in the central control layer is as follows: traverse the IP addresses corresponding to the detection result data, determine whether the IP addresses are all abnormal in all detection nodes (packet loss rate is 100%), and directly retain the detection result data for non-abnormal IP addresses, and proceed to the next step for all abnormal IP addresses. Figure 3In the example, an abnormality occurs in IP1 during a certain period (all detection nodes experience 100% packet loss to IP1). The group with the abnormal IP address in the dynamic address pool is found, and it is determined whether the group has an IP address in the healthy state. If the group has an IP address in the healthy state, the denoising state of the abnormal IP address is changed to the unhealthy state, and the IP address in the healthy state is changed to the active state. Here, at least one healthy IP address needs to be selected to meet the expected number of each group as much as possible. Figure 3 In the example, ip1 is changed to unhealthy state and ip2 is changed to active state. If there is no healthy IP address in the group, the number of active IP addresses in the current group, excluding the abnormal IP address, is determined to see whether it meets the minimum requirement. If it still meets the minimum requirement, the abnormal IP address is changed to unhealthy state. Otherwise, the abnormal IP address is retained. Figure 3 In the example, if IP3 experiences an abnormality, the detection results corresponding to IP3 will be retained. After the abnormal IP address changes to the unhealthy state, the detection results corresponding to the abnormal IP address will be removed from the detection results of that period, and the remaining data will be aggregated to generate alarm indicators.
[0069] After the dynamic address pool is updated after denoising, the task management module re-issues the detection task, and the detection node detects the active IP addresses in the new dynamic address pool in the next cycle.
[0070] In order to prevent the IP addresses in the dynamic address pool from continuously failing to be in an abnormal state, it is necessary to periodically send a single execution task to the detection node so that the detection node performs the detection task on the IP addresses in the abnormal state and the IP addresses in the normal state, and obtains the detection result data corresponding to the IP addresses in the abnormal state and the detection results corresponding to the IP addresses in the normal state; determines whether the detection result data corresponding to the IP addresses in the abnormal state is normal, and if so, adjusts the denoising state corresponding to the IP addresses in the abnormal state to the normal state; determines whether the detection result corresponding to the IP addresses in the normal state is normal, and if not, adjusts the denoising state corresponding to the IP addresses in the normal state to the abnormal state.
[0071] Specifically, in order to prevent the IP addresses in the dynamic address pool from continuously failing to become unhealthy, the address pool management module in the central control device will periodically perform health checks on the dynamic address pool (for example, once an hour), and will issue real-time tasks through the task management module. The detection node will detect the IP addresses in the address pool once and report the detection results. The data aggregation module will summarize the data and return the results to the health check process. If the IP address in the unhealthy state returns to normal (the general judgment condition is that the packet loss rate is 0), it will be changed to the healthy state. For the IP address in the healthy state, if an abnormality occurs, it will be changed to the unhealthy state. Figure 3 In this example, IP1 has returned to a healthy state. By designing the dynamic address pool, the system effectively eliminates noise data and ultimately achieves zero false alarms for network monitoring.
[0072] This method is based on the above dynamic address pool design. The overall idea of real-time denoising is: group the address pool IPs by grouping labels, and have the central control layer summarize the detection results of multiple detection nodes to find the IP addresses with abnormal detection results in all detection nodes. Try to replace the abnormal IP addresses with healthy IP addresses in the group. Because in reality, the abnormality of all detection nodes to a certain IP is most likely due to server restart or IP change operation (server restart may be due to server failure, but it has nothing to do with network link quality), and it is extremely unlikely to occur on a large scale (such as the entire computer room or the entire province). Therefore, this condition can be used to judge the noisy IP. In order to prevent extreme situations, at least the minimum number of IPs in each group will be retained when replacing IPs to ensure that no alarms are missed.
[0073] The following embodiments are used to describe the preset packet sending and receiving algorithm.
[0074] Based on the dynamic address pool at the central control layer, to achieve real-time, accurate, and second-level network monitoring, the small number of detection nodes running in each data center must also support detecting a large number of IP addresses (for example, the operator's public network egress IP addresses need to detect nearly 10,000 IP addresses from various operators in various provinces). Using the traditional ping program process will encounter the following problems:
[0075] 1. The traditional process is serial processing. If batch concurrent processing is required, a subprocess or thread must be used for each ping of a target IP address. This results in significant performance loss and cannot support the detection of large numbers of IP addresses.
[0076] 2. Unlike connection-state protocols such as TCP, the recvmsg operation using raw sockets first processes all received ICMP echo packets and then filters the peer IP address. During concurrent ping operations, if multiple raw sockets are opened using multiple threads, each recvmsg operation will receive ICMP echo data from other threads, resulting in a significant performance waste.
[0077] 3. Ping latency data is obtained by calculating the difference between the time before sending and the time when receiving a data packet. Due to the buffer space when the kernel processes data and the time required for process scheduling, the latency data obtained when detecting large numbers of IP addresses may be higher than the actual value (with an error of more than 10ms). This cannot be used for detection scenarios within IDC data centers (which require an accuracy of 0.1ms) and is also prone to false alarms in other scenarios.
[0078] In order to achieve high-performance and high-precision ping operations for a large number of IP addresses, the present disclosure fully utilizes the characteristics of Go language programs and Linux kernel system calls to develop a high-performance and high-precision packet sending and receiving algorithm logic. Specifically, the above-mentioned multiple detection nodes periodically perform detection tasks based on a preset packet sending and receiving algorithm, and the specific process of obtaining detection result data can include: dividing the IP addresses bound to the detection task into multiple groups through the detection node; using a sending Go coroutine to periodically send ICMP request data packets for the IP addresses in each group of the multiple groups; reading and parsing the ICMP response data packets to obtain the mapping queue corresponding to the sending Go coroutine; wherein the mapping queue includes the timestamp of the received data packet and the timestamp of the sent data packet corresponding to each IP address; based on the data in the mapping queue corresponding to the sending Go coroutine and the reception rate of the ICMP response data packets, the detection result data is obtained.
[0079] Sending a goroutine (Goroutine) is a method of concurrent programming using coroutines in the Go language. Goroutines are a core feature of the Go language, allowing developers to easily write concurrent code without complex thread management and locking mechanisms. The ICMP request packet mentioned above is a type of Internet Control Message Protocol (ICMP) packet, primarily used to query network status or obtain certain information.
[0080] In an optional embodiment, the specific process of using a sending Go coroutine to periodically send ICMP request data packets for the IP addresses in each group in the multiple groups may include: for the IP addresses in each group in the multiple groups, setting a timer and establishing a mapping queue at the beginning of the sending Go coroutine; adding a global mapping relationship for each IP address in the current group; wherein the global mapping relationship includes: the correspondence between the IP address, the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and the mapping queue; wherein the identifier is used to distinguish tasks when there is the same IP address in the IP address pool corresponding to multiple detection tasks; in response to the sending Go coroutine, starting the timer, monitoring the timer and the mapping queue, and when the timer expires, sending a ping request to the IP address in the current group; wherein the ping request data packet includes: the IP address, the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and a sequence number, and the sequence number is used to distinguish multiple data packets sent to an IP address in a detection task.
[0081] The aforementioned Ping request, also known as an ICMP Echo request, is a tool used to test network connections. Ping is a method used for network diagnosis and testing. By sending ICMP echo request packets and receiving echo reply packets, it checks whether the network connection is normal, and tests the network packet loss rate and RTT delay indicators. Computer operating systems usually provide a ping program for a single IP. Among them, RTT (Round-Trip Time) refers to the time from the start of data transmission at the sender to the time the sender receives confirmation from the receiver (the receiver sends confirmation immediately after receiving the data). The aforementioned packet loss rate refers to the ratio of the number of data packets lost over a period of time to the total number of data packets sent during network transmission.
[0082] Furthermore, the specific process of reading and parsing the ICMP response data packet and obtaining the mapping queue corresponding to the sending Go coroutine may include: reading and parsing the ICMP response data packet by the receiving Go coroutine to obtain the timestamp of the ping request data packet and the received data packet, determining the mapping queue from the global mapping relationship through the IP address in the ping request data packet and the identifier that the ICMP protocol data packet corresponding to the IP address can carry, and storing the timestamp of the received data packet in the mapping queue; reading and parsing the time of sending data packet by the kernel time Go coroutine to obtain the timestamp of the ping request data packet and the sent data packet, determining the mapping queue from the global mapping relationship through the IP address in the ping request data packet and the identifier that the ICMP protocol data packet corresponding to the IP address can carry, and storing the timestamp of the sent data packet in the mapping queue.
[0083] Furthermore, the specific process of obtaining the detection result data based on the data in the mapping queue corresponding to the sending Go coroutine and the reception rate of the ICMP response data packet may include: monitoring whether there is data in the mapping queue through the switch operation of the sending Go coroutine; if there is data, obtaining the data in the mapping queue; wherein, for the normally sent and received ICMP protocol data packets, the data obtained are the IP address, the identifier and sequence number that can be carried by the ICMP protocol data packet corresponding to the IP address, the timestamp of the sending data packet and the timestamp of the receiving data packet; based on the timestamp of the sending data packet and the timestamp of the receiving data packet corresponding to each IP obtained from the mapping queue, the delay corresponding to each IP address is determined; if the third IP address in the mapping queue only corresponds to the timestamp of the sending data packet, it is determined that there is a packet loss failure in the third IP address, and based on the number of times the third IP address has a packet loss failure and the total number of data packets sent, the packet loss rate corresponding to the third IP address is determined.
[0084] like Figure 4 The embodiment of the present disclosure provides a flowchart of a preset packet sending and receiving algorithm. The preset packet sending and receiving algorithm adopts a read-write separation structure. Figure 4 The left side of the middle diagram mainly shows the process of sending data packets, and the right side mainly shows the process of receiving data packets. For the process of sending data packets, the large number of IP addresses in the IP address pool are first processed in batches. Each batch of IP addresses uses a sending Go coroutine to periodically send ICMP request packets. While ensuring the efficiency of sending data, the number of Go coroutines is reduced to prevent the scheduling efficiency of the Go coroutine itself and the efficiency of a large number of timers. Each sending Go coroutine initially sets a timer and establishes a Go language channel queue (equivalent to the mapping queue mentioned above). At the same time, a global mapping relationship (addr, id)->channel queue is added to each target IP address, where addr is the target IP address and id is an identifier that can be carried by ICMP protocol packets. It is used to distinguish tasks when there is the same IP address in the address pool of multiple tasks. After sending the Go coroutine to start the timer, the switch operation of the Go language is used to monitor the timer and channel queue at the same time. When the timer expires, a ping request is sent to the target IP. Each ping request packet contains (addr, id, seq), where seq is the sequence number that can be carried by ICMP protocol packets. It is used to distinguish multiple packets sent to a target IP address (a combination of addr and id) in a task.
[0085] For the data packet receiving process, a global raw socket is first established, using the kernel timestamp mechanism. A receiving Goroutine and a kernel time Goroutine are then started: the receiving Goroutine is responsible for reading and parsing the ICMP response packet, obtaining the following information: (addr, id, seq, recvTime), where recvTime is the timestamp of the kernel receiving the packet. Using (addr, id), the corresponding sending Goroutine's channel queue is found in the global mapping table, and the data is distributed to the sending Goroutine. Reading and parsing data packets is a non-time-consuming operation, and ICMP response packets do not return at the same time due to different latency. Therefore, performance can be met with a single Goroutine. The kernel time Goroutine is responsible for reading and parsing the time when the kernel sends the packet, obtaining the following information: (addr, id, seq, sendTime), where sendTime is the timestamp of the kernel sending the packet. Similarly, the corresponding sending Goroutine's channel queue is found through the global mapping table and the data is distributed.
[0086] When the switch operation of the sending Go routine detects data in the channel queue, it reads the data in the channel queue. For each normally sent and received ICMP packet, it can obtain the data (addr, id, seq, sendTime, recvTime). The RTT delay of the packet is the time value obtained by subtracting sendTime from recvTime. The average of multiple packets with the same IP address is the average RTT delay of this IP address. If there is a packet loss failure in the network and no ICMP response packet is received, there is no recvTime data, and the packet is recorded as lost. If count packets are sent to the same IP address and the number of dropped packets is dropped, the packet loss rate is (drop / count*100%). After the sending Go routine receives the last ICMP response data through the channel queue or times out for a certain period of time (due to network packet loss), the RTT delay and packet loss rate results of all IP addresses in the batch are summarized and the detection results can be reported to the central control layer later (as described above).
[0087] Through the above-mentioned preset packet sending and receiving algorithm, the system can detect 10,000 IP data packets per second with a single-core CPU, and the calculation error of network link delay data is within 0.1ms, effectively realizing real-time and accurate second-level network monitoring.
[0088] The following embodiments are used to describe the overall architecture corresponding to the central control layer and the detection layer.
[0089] like Figure 5 The figure shows an overall architecture diagram of a network monitoring system provided by an embodiment of the present disclosure. Figure 5The central control layer is a centralized scheduling program responsible for centralized management of address pools, detection tasks, detection nodes, and providing data aggregation and query functions. Users customize the configuration through the front-end user interface provided by the central control layer. The technical difficulty of the central control layer lies in the control of tasks and real-time denoising of dynamic address pools. The detection layer runs on each detection node (IDC). Each detection node uses a small number of servers and is responsible for executing detection tasks for large quantities of IPs. The detection layer and the central control layer use gRPC two-way communication. The technical difficulty of the detection layer lies in the implementation of high-performance and high-precision detection. The detection layer executes detection tasks according to a customizable period (generally within 10 seconds), and the result data (source label, destination IP label, packet loss rate, latency, etc.) is reported to the central control data aggregation service. The aggregated results are stored in the time series database and pushed to the monitoring alarm service to generate alarms.
[0090] like Figure 6 The figure shows the overall architecture of a central control layer provided by an embodiment of the present disclosure. The central control layer can be divided into a detection node management module, an address pool management module, a task management module, and a data query and data aggregation module. The following describes in detail the corresponding functions of each module:
[0091] 1. Detection node management module:
[0092] a) The detection nodes of the detection layer are connected to the central control layer through gRPC for registration, keep-alive, and two-way communication. The detection node management module subscribes to the task control messages in the message queue and sends them to the detection layer, collects the task results of the detection nodes and publishes them to the message queue.
[0093] b) The program configuration of each detection node can dynamically update some configurations, such as the detection node name, the location of the computer room, the network port internal and external network types, etc. This information can be used as a source label to distinguish the detection nodes when reporting the detection result data.
[0094] c) Provide HTTP interface for front-end user interface to query detection node list and dynamically update configuration.
[0095] 2. Address pool management module:
[0096] a) Centrally manage IP address pools for detection. Each address pool contains multiple target IP addresses to be detected. Each IP address can have corresponding attribute tags, such as the province where the public IP address is located, or the cabinet location where the IDC internal IP address is located. The address pool supports multiple sources such as uploading from Excel, obtaining from the server resource management system, and automatically generating from the public IP address database.
[0097] b) Execute scheduled tasks to regularly check the health of the dynamic address pool and regularly filter the IP addresses in the address pool (select healthy IP addresses from the above sources to generate the address pool). The health check and IP filtering process uses the real-time tasks of the task management module.
[0098] c) Provide HTTP interface for address pool query and configuration update to the front-end user interface.
[0099] 3.Task management module:
[0100] a) Centrally manage various types of detection tasks. Tasks can be divided into regular tasks that are executed periodically and real-time tasks that are executed once in real time. Regular tasks are used for long-term monitoring and alarm tasks, while real-time tasks are used for users' temporary detection tasks, dynamic address pool health checks, and address pool IP screening. Each task can be bound to multiple address pools and multiple detection nodes, and the execution parameters of the task can be specified.
[0101] b) Centralized task scheduling is responsible for sending task control messages to the message queue, aggregating the results of task sending from the message queue, and executing dynamic address pool de-noising logic for invalid noisy IP addresses.
[0102] c) Provides an HTTP interface for task management and a WebSocket interface for executing real-time tasks.
[0103] 4. Data query and data aggregation module:
[0104] a) Data aggregation module aggregates the raw data of packet loss rate and latency obtained from IP detection. For example, for the detection of public network quality, aggregation is performed by the province where the IP is located to monitor the network quality of each province.
[0105] b) The original data and aggregated data will be stored in a time series database to facilitate viewing of historical data.
[0106] c) During the data aggregation process, noise data will be identified and sent to the task management module through the message queue. The task management module executes the dynamic address pool denoising logic and updates the task status in real time to remove the noise in the alarm data.
[0107] d) Data query module, which provides an HTTP interface to the outside world and implements the viewing interface of detection results, including raw data and aggregated data, and supports viewing real-time data and historical data.
[0108] like Figure 7The figure shows the overall architecture of a detection layer provided by an embodiment of the present disclosure. The core logic of the detection layer is: after the program is started, the local configuration file and task cache file are loaded to start a continuously running service; the built-in periodic scheduled task is started to execute regular scheduled detection tasks; the real-time task coroutine pool is started to execute real-time detection tasks; two-way communication is established between gRPC and the server, and keep-alive messages are sent to the server at regular intervals. The message contains the version number of the currently executed task, and the central control layer can judge the consistency between the two ends based on this version number; among them, the keep-alive message is mainly used by the central control layer to confirm whether the detection node is operating normally. Then the central control layer receives the task control message and executes the corresponding task. When the connection is accidentally disconnected, a reconnection operation will be performed:
[0109] When a regular task update message is received, the corresponding periodic scheduled task is updated. This message is used when the user creates or updates a task and when the dynamic address pool denoising logic triggers a task update. When a real-time task start message is received, a coroutine is started in the coroutine pool to execute the specified task. This message is used when the user triggers a real-time task, performs an address pool health check, or filters IP addresses. When a real-time task cancellation message is received, the executing task is canceled using the Go language context mechanism. When a dynamic configuration update message is received, the program's dynamic configuration is updated. The dynamic configuration includes source tags such as the location of the detection node.
[0110] In the above method, network link quality detection is performed based on the self-developed packet receiving and sending algorithm and dynamic address pool, simulating the data packet flow of the business, and realizing second-level monitoring of the data center network link quality, covering the backbone network (DCI), data center network (DCN), operator public network exit, SNAT gateway, public cloud, network equipment detection and other full-scene network quality monitoring. The technical solution supports dynamic adjustment of the monitoring IP address pool, automatic real-time denoising of noisy IP, and high-performance and high-precision detection of network link quality, realizing high real-time monitoring of data center network link quality (network link anomalies can be detected in 10 seconds) and high accuracy (zero false alarms).
[0111] In addition, the present invention uses a self-developed packet receiving and sending algorithm to detect a variety of business traffic links with high performance and high precision. A single-core CPU can detect 10,000 IP packets per second, and the calculation error of network link delay data is below 0.1ms, ensuring the accuracy and high concurrency of network link quality detection of NetEase Data Center, and realizing second-level monitoring of data center network link quality (problems are discovered in 10s). The dynamic address pool design and real-time denoising algorithm are adopted. The detection node will report the noise data to the central control layer in real time. The central control layer makes judgments based on the detection of suspicious noise IPs from all nodes of the detection layer. If it is determined that the noise IP will be blocked in real time, and an available IP will be selected from the dynamic IP address pool for replacement, ultimately achieving zero false alarms for network quality alarms. The centralized task management of the central control layer and the distributed architecture of the detection layer are adopted, which supports users to flexibly configure network link detection tasks. The system automatically updates the dynamic address pool of the detection task, realizing network link quality monitoring of all business scenarios, improving the efficiency of network fault discovery and positioning, shortening the duration of network faults, and reducing the impact of network faults.
[0112] Corresponding to the above method embodiment, the embodiment of the present disclosure further provides a network monitoring device, which is arranged in a central control device, and the central control device is connected to multiple detection nodes, such as Figure 8 As shown, the device includes:
[0113] The address pool creation module 80 is used to create an IP address pool, which includes multiple IP addresses to be detected.
[0114] The task creation module 81 is used to create multiple detection tasks based on the IP address pool; wherein the detection task is bound to at least one IP address in the IP address pool.
[0115] The task issuing module 82 is used to issue multiple detection tasks to multiple detection nodes respectively, so that the multiple detection nodes periodically execute the detection tasks based on the preset packet receiving and sending algorithm, obtain the detection result data, and report the detection result data to the central control device; wherein the detection result data at least includes the packet loss rate and / or delay of the IP address corresponding to the detection task.
[0116] The status update module 83 is used to dynamically update the denoising status corresponding to the IP address in the IP address pool based on the detection result data, and synchronize the denoising status corresponding to the IP address to the detection node; wherein, the detection node only performs detection tasks on IP addresses whose denoising status is active.
[0117] The data aggregation module 84 is used to aggregate the detection result data to obtain aggregated detection results, store the aggregated detection results and perform network monitoring and alarming based on the aggregated detection results.
[0118] The above-mentioned network monitoring device supports users to flexibly configure network link detection tasks and automatically update the address pool of the detection tasks, realizing network link quality monitoring in all business scenarios, improving the efficiency of network fault discovery and positioning, shortening the duration of network faults, and reducing the impact of network faults.
[0119] Furthermore, the above-mentioned device also includes a state maintenance module, which is used to: after creating multiple detection tasks based on the IP address pool, maintain a denoising state belonging to the corresponding detection task for each IP address bound to the detection task; wherein the denoising state is used to indicate whether the IP address is currently abnormal.
[0120] Furthermore, the above-mentioned device also includes a state setting module, which is used to: after issuing multiple detection tasks to multiple detection nodes respectively, perform the following operations for each detection task: set the denoising state corresponding to a specified number of IP addresses bound to the detection task to an active state, and set the denoising state corresponding to the IP addresses other than the active state among the IP addresses bound to the detection task to a normal state, so that the detection node performs the detection task on the IP address in the active state and obtains the detection result data.
[0121] Furthermore, the above-mentioned status update module 83 is used to: if the detection result data corresponding to the first IP address in the active state is abnormal, determine whether there is an IP address with a normal denoising state among the IP addresses bound to the detection task; if so, adjust the denoising state corresponding to the first IP address to an abnormal state, and select a second IP address from the IP addresses in the normal state among the IP addresses bound to the detection task, and adjust the denoising state corresponding to the second IP address to an active state.
[0122] Furthermore, the number of the second IP addresses is the same as the number of the first IP addresses, or the number of the second IP addresses meets the first quantity requirement.
[0123] Furthermore, the above-mentioned device also includes a state adjustment module, which is used to: if there is no IP address with a normal denoising state among the IP addresses bound to the detection task, determine whether the IP addresses in the active state among the IP addresses bound to the detection task meet the second quantity requirement if the denoising state corresponding to the first IP address is adjusted to an abnormal state; if so, adjust the denoising state corresponding to the first IP address to an abnormal state; if not, keep the denoising state corresponding to the first IP address as an active state.
[0124] Furthermore, the above-mentioned data aggregation module 84 is used to: if the denoising state corresponding to the first IP address is adjusted to an abnormal state, delete the detection result data corresponding to the first IP address in the detection result data to obtain updated detection result data; and perform aggregation processing on the updated detection result data to obtain an aggregated detection result.
[0125] Furthermore, the above-mentioned device also includes a status timing update module, which is used to: regularly send a single execution task to the detection node, so that the detection node performs the detection task on the IP address in the abnormal state and the IP address in the normal state, and obtains the detection result data corresponding to the IP address in the abnormal state and the detection result corresponding to the IP address in the normal state; determines whether the detection result data corresponding to the IP address in the abnormal state is normal, and if it is normal, adjusts the denoising state corresponding to the IP address in the abnormal state to the normal state; determines whether the detection result corresponding to the IP address in the normal state is normal, and if it is not normal, adjusts the denoising state corresponding to the IP address in the normal state to the abnormal state.
[0126] Furthermore, the above-mentioned task dispatching module 82 is used to: divide the IP addresses bound to the detection task into multiple groups through the detection node; use a sending Go coroutine to periodically send ICMP request data packets for the IP addresses in each group in the multiple groups; read and parse the ICMP response data packets to obtain the mapping queue corresponding to the sending Go coroutine; wherein the mapping queue includes the timestamp of the received data packet and the timestamp of the sent data packet corresponding to each IP address; based on the data in the mapping queue corresponding to the sending Go coroutine and the reception rate of the ICMP response data packet, the detection result data is obtained.
[0127] Furthermore, the above-mentioned task dispatching module 82 is also used to: for the IP address in each group in multiple groups, set a timer and establish a mapping queue when the Go coroutine is initially sent; add a global mapping relationship for each IP address in the current group; wherein, the global mapping relationship includes: the correspondence between the IP address, the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and the mapping queue; wherein, the identifier is used to distinguish tasks when there is the same IP address in the IP address pool corresponding to multiple detection tasks; in response to sending the Go coroutine, start the timer, listen to the timer and the mapping queue, and when the timer expires, send a ping request to the IP address in the current group; wherein, the ping request data packet includes: the IP address, the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and the sequence number, and the sequence number is used to distinguish multiple data packets sent to an IP address in a detection task.
[0128] Furthermore, the above-mentioned task dispatching module 82 is also used to: read and parse the ICMP response data packet by the receiving Go coroutine to obtain the timestamp of the ping request data packet and the received data packet, determine the mapping queue from the global mapping relationship through the IP address in the ping request data packet and the identifier that the ICMP protocol data packet corresponding to the IP address can carry, and store the timestamp of the received data packet in the mapping queue; read and parse the time of sending data packet by the kernel time Go coroutine to obtain the timestamp of the ping request data packet and the sent data packet, determine the mapping queue from the global mapping relationship through the IP address in the ping request data packet and the identifier that the ICMP protocol data packet corresponding to the IP address can carry, and store the timestamp of the sent data packet in the mapping queue.
[0129] Furthermore, the task dispatching module 82 is also used to: monitor whether there is data in the mapping queue by sending a switch operation of the Go coroutine; if there is data, obtain the data in the mapping queue; wherein, for the normally sent and received ICMP protocol data packets, the data obtained are the IP address, the identifier and sequence number that can be carried by the ICMP protocol data packet corresponding to the IP address, the timestamp of the sent data packet and the timestamp of the received data packet; based on the timestamp of the sent data packet and the timestamp of the received data packet corresponding to each IP obtained from the mapping queue, determine the delay corresponding to each IP address; if the third IP address in the mapping queue only corresponds to the timestamp of the sent data packet, determine that there is a packet loss failure in the third IP address, and determine the packet loss rate corresponding to the third IP address based on the number of packet loss failures at the third IP address and the total number of data packets sent.
[0130] The network monitoring device provided in the embodiment of the present disclosure has the same implementation principle and technical effects as those of the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the device embodiment, reference can be made to the corresponding content in the aforementioned method embodiment.
[0131] The present disclosure also provides an electronic device, such as Figure 9 As shown, the electronic device includes a processor and a memory, the memory stores machine-executable instructions that can be executed by the processor, and the processor executes the machine-executable instructions to implement the above-mentioned network monitoring method.
[0132] Specifically, the above-mentioned network monitoring method is applied to a central control device, which is communicatively connected to a plurality of detection nodes. The method includes: creating an IP address pool, which includes a plurality of IP addresses to be detected; creating a plurality of detection tasks based on the IP address pool; wherein the detection task is bound to at least one IP address in the IP address pool; issuing a plurality of detection tasks to a plurality of detection nodes respectively, so that the plurality of detection nodes periodically execute the detection tasks based on a preset packet receiving and sending algorithm, obtain detection result data, and report the detection result data to the central control device; wherein the detection result data includes at least the packet loss rate and / or delay of the IP address corresponding to the detection task; based on the detection result data, dynamically updating the denoising status corresponding to the IP address in the IP address pool, and synchronizing the denoising status corresponding to the IP address to the detection node; wherein the detection node only executes the detection task for the IP address whose denoising status is active; aggregating the detection result data to obtain the aggregated detection result, storing the aggregated detection result and performing network monitoring alarm based on the aggregated detection result.
[0133] The above network monitoring method supports users to flexibly configure network link detection tasks and automatically update the address pool of the detection tasks, realizing network link quality monitoring in all business scenarios, improving the efficiency of network fault detection and location, shortening the duration of network faults, and reducing the impact of network faults.
[0134] In an optional embodiment, after creating multiple detection tasks based on the IP address pool, the above method also includes: maintaining a denoising state belonging to the corresponding detection task for each IP address bound to the detection task; wherein the denoising state is used to indicate whether the IP address is currently abnormal.
[0135] In an optional embodiment, after issuing multiple detection tasks to multiple detection nodes respectively, the above method also includes: performing the following operations for each detection task: setting the denoising status corresponding to a specified number of IP addresses bound to the detection task to an active state, and setting the denoising status corresponding to the IP addresses other than the active state among the IP addresses bound to the detection task to a normal state, so that the detection node performs the detection task on the IP address in the active state to obtain detection result data.
[0136] In an optional embodiment, the above-mentioned step of dynamically updating the denoising status corresponding to the IP addresses in the IP address pool based on the detection result data includes: if the detection result data corresponding to the first IP address in the active state is abnormal, determining whether there is an IP address with a normal denoising status among the IP addresses bound to the detection task; if so, adjusting the denoising status corresponding to the first IP address to an abnormal state, and selecting a second IP address from the IP addresses in the normal state among the IP addresses bound to the detection task, and adjusting the denoising status corresponding to the second IP address to an active state.
[0137] In an optional embodiment, the number of the second IP addresses is the same as the number of the first IP addresses, or the number of the second IP addresses meets the first quantity requirement.
[0138] In an optional embodiment, the above method also includes: if there is no IP address with a normal denoising status among the IP addresses bound to the detection task, determining whether the IP addresses in the active state among the IP addresses bound to the detection task meet the second quantity requirement if the denoising status corresponding to the first IP address is adjusted to an abnormal state; if so, adjusting the denoising status corresponding to the first IP address to an abnormal state; if not, retaining the denoising status corresponding to the first IP address as an active state.
[0139] In an optional embodiment, the above-mentioned step of aggregating the detection result data to obtain the aggregated detection result includes: if the denoising state corresponding to the first IP address is adjusted to an abnormal state, deleting the detection result data corresponding to the first IP address in the detection result data to obtain updated detection result data; aggregating the updated detection result data to obtain the aggregated detection result.
[0140] In an optional embodiment, the above method also includes: regularly sending a single execution task to the detection node so that the detection node performs the detection task on the IP address in the abnormal state and the IP address in the normal state, and obtains the detection result data corresponding to the IP address in the abnormal state and the detection result corresponding to the IP address in the normal state; determining whether the detection result data corresponding to the IP address in the abnormal state is normal, and if it is normal, adjusting the denoising state corresponding to the IP address in the abnormal state to the normal state; determining whether the detection result corresponding to the IP address in the normal state is normal, and if it is not normal, adjusting the denoising state corresponding to the IP address in the normal state to the abnormal state.
[0141] In an optional embodiment, the above-mentioned multiple detection nodes periodically execute the detection task based on a preset packet receiving and sending algorithm, and the steps of obtaining detection result data include: dividing the IP address bound to the detection task into multiple groups through the detection node; using a sending Go coroutine to periodically send ICMP request data packets for the IP address in each group in the multiple groups; reading and parsing the ICMP response data packets to obtain the mapping queue corresponding to the sending Go coroutine; wherein the mapping queue includes the timestamp of the received data packet and the timestamp of the sent data packet corresponding to each IP address; and obtaining the detection result data based on the data in the mapping queue corresponding to the sending Go coroutine and the reception rate of the ICMP response data packets.
[0142] In an optional embodiment, the above-mentioned step of using a sending Go coroutine to periodically send ICMP request data packets for the IP addresses in each group in the multiple groups includes: for the IP addresses in each group in the multiple groups, setting a timer and establishing a mapping queue at the beginning of the sending Go coroutine; adding a global mapping relationship for each IP address in the current group; wherein the global mapping relationship includes: the correspondence between the IP address, the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and the mapping queue; wherein the identifier is used to distinguish tasks when there is the same IP address in the IP address pool corresponding to multiple detection tasks; in response to the sending Go coroutine, starting the timer, monitoring the timer and the mapping queue, and when the timer expires, sending a ping request to the IP address in the current group; wherein the ping request data packet includes: the IP address, the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and a sequence number, and the sequence number is used to distinguish multiple data packets sent to an IP address in a detection task.
[0143] In an optional embodiment, the above-mentioned reading and parsing of ICMP response data packets to obtain the mapping queue corresponding to the sending Go coroutine includes: reading and parsing the ICMP response data packet by the receiving Go coroutine to obtain the timestamp of the ping request data packet and the received data packet, and determining the mapping queue from the global mapping relationship through the IP address in the ping request data packet and the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and storing the timestamp of the received data packet in the mapping queue; reading and parsing the time of sending data packets by the kernel time Go coroutine to obtain the timestamp of the ping request data packet and the sent data packet, and determining the mapping queue from the global mapping relationship through the IP address in the ping request data packet and the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and storing the timestamp of the sent data packet in the mapping queue.
[0144] In an optional embodiment, the above-mentioned step of obtaining the detection result data based on the data in the mapping queue corresponding to the sending Go coroutine and the reception rate of the ICMP response data packet includes: monitoring whether there is data in the mapping queue through the switch operation of the sending Go coroutine; if there is data, obtaining the data in the mapping queue; wherein, for the normally sent and received ICMP protocol data packets, the data obtained are the IP address, the identifier and sequence number that can be carried by the ICMP protocol data packet corresponding to the IP address, the timestamp of the sending data packet and the timestamp of the receiving data packet; based on the timestamp of the sending data packet and the timestamp of the receiving data packet corresponding to each IP obtained from the mapping queue, the delay corresponding to each IP address is determined; if the third IP address in the mapping queue only corresponds to the timestamp of the sending data packet, it is determined that there is a packet loss failure in the third IP address, and based on the number of times the third IP address has a packet loss failure and the total number of data packets sent, the packet loss rate corresponding to the third IP address is determined.
[0145] Furthermore, Figure 9 The electronic device shown further includes a bus 102 and a communication interface 103 , and the processor 101 , the communication interface 103 and the memory 100 are connected via the bus 102 .
[0146] The memory 100 may include a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk storage. The communication connection between the system network element and at least one other network element is achieved through at least one communication interface 103 (which may be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. may be used. The bus 102 may be an ISA bus, a PCI bus, or an EISA bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 9 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0147] The processor 101 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by an integrated logic circuit of hardware in the processor 101 or by instructions in the form of software. The above-mentioned processor 101 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gates or transistor logic devices, or discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present disclosure can be implemented or executed. The general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present disclosure can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as a random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or register. The storage medium is located in the memory 100, and the processor 101 reads the information in the memory 100 and, in conjunction with its hardware, completes the steps of the method of the aforementioned embodiment.
[0148] The embodiment of the present disclosure also provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are called and executed by the processor, the computer-executable instructions prompt the processor to implement the above-mentioned network monitoring method. The specific implementation can be found in the method embodiment, which will not be repeated here.
[0149] Specifically, the above-mentioned network monitoring method is applied to a central control device, which is communicatively connected to a plurality of detection nodes. The method includes: creating an IP address pool, which includes a plurality of IP addresses to be detected; creating a plurality of detection tasks based on the IP address pool; wherein the detection task is bound to at least one IP address in the IP address pool; issuing a plurality of detection tasks to a plurality of detection nodes respectively, so that the plurality of detection nodes periodically execute the detection tasks based on a preset packet receiving and sending algorithm, obtain detection result data, and report the detection result data to the central control device; wherein the detection result data includes at least the packet loss rate and / or delay of the IP address corresponding to the detection task; based on the detection result data, dynamically updating the denoising status corresponding to the IP address in the IP address pool, and synchronizing the denoising status corresponding to the IP address to the detection node; wherein the detection node only executes the detection task for the IP address whose denoising status is active; aggregating the detection result data to obtain the aggregated detection result, storing the aggregated detection result and performing network monitoring alarm based on the aggregated detection result.
[0150] The above network monitoring method supports users to flexibly configure network link detection tasks and automatically update the address pool of the detection tasks, realizing network link quality monitoring in all business scenarios, improving the efficiency of network fault detection and location, shortening the duration of network faults, and reducing the impact of network faults.
[0151] In an optional embodiment, after creating multiple detection tasks based on the IP address pool, the above method also includes: maintaining a denoising state belonging to the corresponding detection task for each IP address bound to the detection task; wherein the denoising state is used to indicate whether the IP address is currently abnormal.
[0152] In an optional embodiment, after issuing multiple detection tasks to multiple detection nodes respectively, the above method also includes: performing the following operations for each detection task: setting the denoising status corresponding to a specified number of IP addresses bound to the detection task to an active state, and setting the denoising status corresponding to the IP addresses other than the active state among the IP addresses bound to the detection task to a normal state, so that the detection node performs the detection task on the IP address in the active state to obtain detection result data.
[0153] In an optional embodiment, the above-mentioned step of dynamically updating the denoising status corresponding to the IP addresses in the IP address pool based on the detection result data includes: if the detection result data corresponding to the first IP address in the active state is abnormal, determining whether there is an IP address with a normal denoising status among the IP addresses bound to the detection task; if so, adjusting the denoising status corresponding to the first IP address to an abnormal state, and selecting a second IP address from the IP addresses in the normal state among the IP addresses bound to the detection task, and adjusting the denoising status corresponding to the second IP address to an active state.
[0154] In an optional embodiment, the number of the second IP addresses is the same as the number of the first IP addresses, or the number of the second IP addresses meets the first quantity requirement.
[0155] In an optional embodiment, the above method also includes: if there is no IP address with a normal denoising status among the IP addresses bound to the detection task, determining whether the IP addresses in the active state among the IP addresses bound to the detection task meet the second quantity requirement if the denoising status corresponding to the first IP address is adjusted to an abnormal state; if so, adjusting the denoising status corresponding to the first IP address to an abnormal state; if not, retaining the denoising status corresponding to the first IP address as an active state.
[0156] In an optional embodiment, the above-mentioned step of aggregating the detection result data to obtain the aggregated detection result includes: if the denoising state corresponding to the first IP address is adjusted to an abnormal state, deleting the detection result data corresponding to the first IP address in the detection result data to obtain updated detection result data; aggregating the updated detection result data to obtain the aggregated detection result.
[0157] In an optional embodiment, the above method also includes: regularly sending a single execution task to the detection node so that the detection node performs the detection task on the IP address in the abnormal state and the IP address in the normal state, and obtains the detection result data corresponding to the IP address in the abnormal state and the detection result corresponding to the IP address in the normal state; determining whether the detection result data corresponding to the IP address in the abnormal state is normal, and if it is normal, adjusting the denoising state corresponding to the IP address in the abnormal state to the normal state; determining whether the detection result corresponding to the IP address in the normal state is normal, and if it is not normal, adjusting the denoising state corresponding to the IP address in the normal state to the abnormal state.
[0158] In an optional embodiment, the above-mentioned multiple detection nodes periodically execute the detection task based on a preset packet receiving and sending algorithm, and the steps of obtaining detection result data include: dividing the IP address bound to the detection task into multiple groups through the detection node; using a sending Go coroutine to periodically send ICMP request data packets for the IP address in each group in the multiple groups; reading and parsing the ICMP response data packets to obtain the mapping queue corresponding to the sending Go coroutine; wherein the mapping queue includes the timestamp of the received data packet and the timestamp of the sent data packet corresponding to each IP address; and obtaining the detection result data based on the data in the mapping queue corresponding to the sending Go coroutine and the reception rate of the ICMP response data packets.
[0159] In an optional embodiment, the above-mentioned step of using a sending Go coroutine to periodically send ICMP request data packets for the IP addresses in each group in the multiple groups includes: for the IP addresses in each group in the multiple groups, setting a timer and establishing a mapping queue at the beginning of the sending Go coroutine; adding a global mapping relationship for each IP address in the current group; wherein the global mapping relationship includes: the correspondence between the IP address, the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and the mapping queue; wherein the identifier is used to distinguish tasks when there is the same IP address in the IP address pool corresponding to multiple detection tasks; in response to the sending Go coroutine, starting the timer, monitoring the timer and the mapping queue, and when the timer expires, sending a ping request to the IP address in the current group; wherein the ping request data packet includes: the IP address, the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and a sequence number, and the sequence number is used to distinguish multiple data packets sent to an IP address in a detection task.
[0160] In an optional embodiment, the above-mentioned reading and parsing of ICMP response data packets to obtain the mapping queue corresponding to the sending Go coroutine includes: reading and parsing the ICMP response data packet by the receiving Go coroutine to obtain the timestamp of the ping request data packet and the received data packet, and determining the mapping queue from the global mapping relationship through the IP address in the ping request data packet and the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and storing the timestamp of the received data packet in the mapping queue; reading and parsing the time of sending data packets by the kernel time Go coroutine to obtain the timestamp of the ping request data packet and the sent data packet, and determining the mapping queue from the global mapping relationship through the IP address in the ping request data packet and the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and storing the timestamp of the sent data packet in the mapping queue.
[0161] In an optional embodiment, the above-mentioned step of obtaining the detection result data based on the data in the mapping queue corresponding to the sending Go coroutine and the reception rate of the ICMP response data packet includes: monitoring whether there is data in the mapping queue through the switch operation of the sending Go coroutine; if there is data, obtaining the data in the mapping queue; wherein, for the normally sent and received ICMP protocol data packets, the data obtained are the IP address, the identifier and sequence number that can be carried by the ICMP protocol data packet corresponding to the IP address, the timestamp of the sending data packet and the timestamp of the receiving data packet; based on the timestamp of the sending data packet and the timestamp of the receiving data packet corresponding to each IP obtained from the mapping queue, the delay corresponding to each IP address is determined; if the third IP address in the mapping queue only corresponds to the timestamp of the sending data packet, it is determined that there is a packet loss failure in the third IP address, and based on the number of times the third IP address has a packet loss failure and the total number of data packets sent, the packet loss rate corresponding to the third IP address is determined.
[0162] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a terminal device, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present disclosure. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0163] In the description of this disclosure, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings and are intended solely to facilitate the description of this disclosure and simplify the description. They do not indicate or imply that the devices or components referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limitations on this disclosure. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.
[0164] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present disclosure, which are used to illustrate the technical solutions of the present disclosure, rather than to limit them. The scope of protection of the present disclosure is not limited thereto. Although the present disclosure has been described in detail with reference to the above-described embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above-described embodiments within the technical scope disclosed in the present disclosure, or replace some of the technical features therein with equivalents. Such modifications, changes, or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should be included in the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure shall be subject to the scope of protection of the claims.
Claims
1. A network monitoring method, characterized in that: The method is applied to a central control device, the central control device being communicatively connected to a plurality of detection nodes, and the method includes: Creating an IP address pool, wherein the IP address pool includes a plurality of IP addresses to be detected; Creating a plurality of detection tasks based on the IP address pool; wherein the detection task is bound to at least one IP address in the IP address pool; The plurality of detection tasks are respectively issued to the plurality of detection nodes, so that the plurality of detection nodes periodically execute the detection tasks based on a preset packet sending and receiving algorithm, obtain detection result data, and report the detection result data to the central control device; wherein the detection result data at least includes a packet loss rate and / or a delay of the IP address corresponding to the detection task; Based on the detection result data, dynamically update the denoising status corresponding to the IP address in the IP address pool, and synchronize the denoising status corresponding to the IP address to the detection node; wherein the detection node only performs detection tasks for IP addresses whose denoising status is active; Aggregate the detection result data to obtain aggregated detection results, store the aggregated detection results, and perform network monitoring and alarming based on the aggregated detection results.
2. The method according to claim 1, characterized in that After the step of creating multiple detection tasks based on the IP address pool, the method further includes: A denoising state belonging to the corresponding detection task is maintained for each IP address bound to the detection task; wherein the denoising state is used to indicate whether the IP address is currently abnormal.
3. The method according to claim 1, characterized in that After the step of respectively issuing the plurality of detection tasks to the plurality of detection nodes, the method further includes: For each detection task, perform the following operations: The denoising status corresponding to the specified number of IP addresses bound to the detection task is set to the active state, and the denoising status corresponding to the IP addresses other than the active state among the IP addresses bound to the detection task is set to the normal state, so that the detection node performs the detection task on the IP addresses in the active state and obtains the detection result data.
4. The method according to claim 3, characterized in that The step of dynamically updating the denoising status corresponding to the IP addresses in the IP address pool based on the detection result data includes: If the detection result data corresponding to the first IP address in the active state is abnormal, determining whether there is an IP address in a normal denoising state among the IP addresses bound to the detection task; If so, the denoising state corresponding to the first IP address is adjusted to an abnormal state, and a second IP address is selected from the IP addresses in the normal state among the IP addresses bound to the detection task, and the denoising state corresponding to the second IP address is adjusted to an active state.
5. The method according to claim 4, characterized in that The number of the second IP addresses is the same as the number of the first IP addresses, or the number of the second IP addresses meets the first quantity requirement.
6. The method according to claim 4, characterized in that The method further comprises: If there is no IP address with a normal denoising state among the IP addresses bound to the detection task, determining whether the active IP addresses among the IP addresses bound to the detection task meet the second quantity requirement if the denoising state corresponding to the first IP address is adjusted to an abnormal state; If satisfied, adjust the denoising state corresponding to the first IP address to an abnormal state; If not, the denoising state corresponding to the first IP address is kept active.
7. The method according to claim 4 or 6, characterized in that The step of aggregating the detection result data to obtain an aggregated detection result includes: If the denoising state corresponding to the first IP address is adjusted to an abnormal state, the detection result data corresponding to the first IP address in the detection result data is deleted to obtain updated detection result data; Aggregation processing is performed on the updated detection result data to obtain an aggregated detection result.
8. The method according to claim 4 or 6, characterized in that The method further comprises: Periodically issuing a single execution task to the detection node, so that the detection node performs the detection task on the IP address in the abnormal state and the IP address in the normal state, and obtains detection result data corresponding to the IP address in the abnormal state and detection results corresponding to the IP address in the normal state; Determine whether the detection result data corresponding to the IP address in the abnormal state is normal, and if normal, adjust the denoising state corresponding to the IP address in the abnormal state to a normal state; Determine whether the detection result corresponding to the IP address in the normal state is normal, and if not, adjust the denoising state corresponding to the IP address in the normal state to an abnormal state.
9. The method according to claim 1, characterized in that The multiple detection nodes periodically perform the detection task based on a preset packet sending and receiving algorithm to obtain detection result data, including: Dividing the IP addresses bound to the detection task into a plurality of groups by the detection node; For each IP address in the plurality of packets, use a sending Goroutine to periodically send an ICMP request packet. Read and parse the ICMP response data packet to obtain the mapping queue corresponding to the sending Go coroutine; wherein the mapping queue includes the timestamp of the received data packet and the timestamp of the sent data packet corresponding to each IP address; The detection result data is obtained based on the data in the mapping queue corresponding to the sending Go coroutine and the reception rate of the ICMP response data packet.
10. The method according to claim 9, characterized in that The step of using a sending Go coroutine to periodically send an ICMP request data packet for the IP address in each of the multiple groups includes: For each IP address in the plurality of groups, a timer is set and a mapping queue is established when the sending Go routine is initiated; Adding a global mapping relationship for each IP address in the current group; wherein the global mapping relationship includes: a correspondence between an IP address, an identifier that can be carried by an ICMP protocol packet corresponding to the IP address, and the mapping queue; wherein the identifier is used to distinguish tasks when the same IP address exists in the IP address pool corresponding to multiple detection tasks; In response to sending a Go coroutine to start a timer, monitor the timer and the mapping queue, and when the timer expires, send a ping request to the IP address in the current group; wherein the ping request data packet includes: an IP address, an identifier and a sequence number that can be carried by an ICMP protocol data packet corresponding to the IP address, and the sequence number is used to distinguish multiple data packets sent to an IP address in a detection task.
11. The method according to claim 10, characterized in that The step of reading and parsing the ICMP response data packet to obtain the mapping queue corresponding to the sending Go coroutine includes: The receiving Go coroutine reads and parses the ICMP response data packet to obtain the timestamp of the ping request data packet and the received data packet, determines the mapping queue from the global mapping relationship through the IP address in the ping request data packet and the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and stores the timestamp of the received data packet in the mapping queue accordingly; The time of sending the data packet is read and parsed through the kernel time Go coroutine to obtain the timestamps of the ping request data packet and the sending data packet. The mapping queue is determined from the global mapping relationship through the IP address in the ping request data packet and the identifier that can be carried by the ICMP protocol data packet corresponding to the IP address, and the timestamp of sending the data packet is stored in the mapping queue.
12. The method according to claim 10, characterized in that The step of obtaining detection result data based on the data in the mapping queue corresponding to the sending Go coroutine and the reception rate of the ICMP response data packet includes: Monitor whether there is data in the mapping queue by sending the switch operation of the Go coroutine; If data is stored, obtain the data in the mapping queue; wherein, for ICMP protocol packets sent and received normally, the data obtained are the IP address, the identifier and sequence number that can be carried by the ICMP protocol packet corresponding to the IP address, the timestamp of sending the packet, and the timestamp of receiving the packet; Determine the delay corresponding to each IP address based on the timestamp of the sent data packet and the timestamp of the received data packet corresponding to each IP address obtained from the mapping queue; If the third IP address in the mapping queue only corresponds to the timestamp of sending the data packet, it is determined that the third IP address has a packet loss failure, and based on the number of times the third IP address has a packet loss failure and the total number of data packets sent, the packet loss rate corresponding to the third IP address is determined.
13. A network monitoring device, characterized in that: The device is provided in a central control device, the central control device is communicatively connected with a plurality of detection nodes, and the device includes: An address pool creation module, configured to create an IP address pool, wherein the IP address pool includes a plurality of IP addresses to be detected; A task creation module, configured to create a plurality of detection tasks based on the IP address pool; wherein the detection task is bound to at least one IP address in the IP address pool; A task issuing module, configured to issue the multiple detection tasks to the multiple detection nodes respectively, so that the multiple detection nodes periodically execute the detection tasks based on a preset packet sending and receiving algorithm, obtain detection result data, and report the detection result data to the central control device; wherein the detection result data at least includes the packet loss rate and / or delay of the IP address corresponding to the detection task; A status update module is configured to dynamically update the denoising status corresponding to the IP addresses in the IP address pool based on the detection result data, and synchronize the denoising status corresponding to the IP addresses to the detection node; wherein the detection node only performs detection tasks for IP addresses whose denoising status is active; The data aggregation module is used to aggregate the detection result data to obtain aggregated detection results, store the aggregated detection results and perform network monitoring and alarming based on the aggregated detection results.
14. An electronic device, characterized in that: The invention comprises a processor and a memory, wherein the memory stores machine-executable instructions that can be executed by the processor, and the processor executes the machine-executable instructions to implement the network monitoring method according to any one of claims 1 to 12.
15. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions prompt the processor to implement the network monitoring method according to any one of claims 1 to 12.