Routing interruption detection method and device, equipment and storage medium

By deploying observation points in the network to collect BGP routing data, determining the routing information of the target AS and extracting its features, and using an interruption detection model, the system achieves automated detection of AS interruptions. This solves the detection difficulty problem caused by the autonomy of the BGP protocol and improves the detection accuracy and precision.

CN121000653APending Publication Date: 2025-11-21TSINGHUA UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511121288.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-11
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

In existing technologies, the autonomy of the BGP protocol makes network fault detection difficult, and the possibility of misoperation and malicious attacks is high, making AS outage detection particularly difficult.

Method used

By deploying observation points to collect BGP routing data, the routing information of the target AS is determined, including the path withdrawal ratio and IP prefix withdrawal ratio, and an interruption detection model is used for automated detection.

Benefits of technology

It improves the accuracy and precision of AS interrupt detection, reduces false alarms and false negatives, and achieves automated interrupt detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000653A_ABST
    Figure CN121000653A_ABST
Patent Text Reader

Abstract

The invention provides a routing interruption detection method, device and equipment and a storage medium, and the method comprises the steps: collecting the BGP (border gateway protocol) routing data of a control plane in a network through an observation point, and determining a target AS (autonomous system) with routing change and the routing information of the target AS based on the BGP routing data, the routing information of the target AS comprises a path withdrawing proportion of the target AS, a total number of paths of the target AS, an IP prefix withdrawing proportion of the target AS, a total number of IP prefixes of the target AS, a next hop withdrawing proportion of an observation point and a total number of next hops of the observation point, and finally performing feature extraction on the routing information of the target AS to obtain an AS routing feature vector. And inputting the AS routing feature vector into an interruption detection model for interruption detection to obtain an interruption detection result so as to judge whether the target AS is interrupted or not. According to the embodiment of the invention, routing interruption detection can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of route detection, and more specifically, to a method, apparatus, device, and storage medium for route interruption detection. Background Technology

[0002] The current Internet uses the Border Gateway Protocol (BGP) for inter-domain routing. BGP is a distributed protocol that requires each Autonomous System (AS) in the Internet to perform its own route selection and advertise its chosen route path to neighboring ASs. However, it does not impose any restrictions on the route selection or the route path advertised by each AS. Therefore, ASs have a high degree of autonomy in advertising paths. This increases the possibility of network failures due to misoperation, provides room for malicious network attacks, and increases the difficulty of route failure detection.

[0003] Common routing failures include AS outages, which occur when an AS suddenly fails and becomes unable to provide services. A key manifestation of an AS outage is the sudden issuance of a large number of IP prefix withdrawal messages, making these IP prefixes unreachable and consequently rendering services inaccessible. Therefore, AS outage detection is a problem worthy of study. Summary of the Invention

[0004] In view of this, this application provides a routing interruption detection method, apparatus, device, and storage medium to at least solve the problems existing in the related art.

[0005] Specifically, this application is implemented through the following technical solution:

[0006] This application provides a routing interruption detection method, comprising: collecting Border Gateway Protocol (BGP) routing data of the control plane in the network through observation points; wherein the observation points are routing data collection nodes deployed in the network;

[0007] Based on the BGP routing data, the target Autonomous System (AS) that has undergone routing changes is determined, along with the routing information of the target AS. The routing information of the target AS includes the path withdrawal ratio of the target AS, the total number of paths of the target AS, the IP prefix withdrawal ratio of the target AS, the total number of IP prefixes of the target AS, the next-hop withdrawal ratio of the observation point, and the total number of next hops of the observation point.

[0008] The routing information of the target AS is used to extract features to obtain an AS routing feature vector, and the AS routing feature vector is input into an interruption detection model to perform interruption detection and obtain an interruption detection result; the interruption detection result is used to indicate whether the target AS has been interrupted.

[0009] This application also provides a routing interruption detection device, the device comprising:

[0010] The acquisition module is used to acquire Border Gateway Protocol (BGP) routing data of the control plane in the network through observation points; the observation points are routing data acquisition nodes deployed in the network.

[0011] The determination module is used to determine the target Autonomous System (AS) that has undergone a route change and the routing information of the target AS based on the BGP routing data. The routing information of the target AS includes the path withdrawal ratio of the target AS, the total number of paths of the target AS, the IP prefix withdrawal ratio of the target AS, the total number of IP prefixes of the target AS, the next-hop withdrawal ratio of the observation point, and the total number of next hops of the observation point.

[0012] The detection module is used to extract features from the routing information of the target AS to obtain an AS routing feature vector, and input the AS routing feature vector into the interruption detection model to perform interruption detection and obtain an interruption detection result; the interruption detection result is used to indicate whether the target AS has been interrupted.

[0013] This application also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of any of the routing interruption detection methods described in the foregoing embodiments.

[0014] This application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of any of the routing interruption detection methods described in the foregoing embodiments.

[0015] This application also provides a computer program product, including a computer program that, when run by a processor, performs the steps of any of the possible routing interruption detection methods described above.

[0016] The technical solutions provided by the embodiments of this application may include the following beneficial effects:

[0017] In this embodiment of the application, BGP routing data is automatically collected by deployed observation points. The target AS and its routing information are determined based on the BGP routing data. Model inference is then performed based on the routing information of the target AS, which can automatically detect whether the target AS has been interrupted.

[0018] Furthermore, since the routing information of the target AS includes the path withdrawal ratio of the target AS, the total number of paths of the target AS, the IP prefix withdrawal ratio of the target AS, the total number of IP prefixes of the target AS, the next-hop withdrawal ratio of the observation point, and the total number of next hops of the observation point, that is, the routing information of the target AS corresponds to both the observation point dimension and the dimension to be observed (the target AS that has changed), the information coverage is large. Thus, the detection accuracy can be improved when performing interruption detection.

[0019] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this specification. Attached Figure Description

[0020] Figure 1 This is a flowchart illustrating a routing interruption detection method according to an exemplary embodiment of this application;

[0021] Figure 2 This is an exemplary embodiment of the present application illustrating an AS withdrawal path percentage histogram;

[0022] Figure 3 This is an exemplary embodiment of the present application illustrating an AS withdrawal next-hop percentage histogram;

[0023] Figure 4 This is a flowchart illustrating an exemplary embodiment of the present application for interruption detection;

[0024] Figure 5 This is an exemplary embodiment of the present application illustrating a training set and test set size distribution diagram;

[0025] Figure 6 This is an exemplary embodiment of the present application illustrating a detection result histogram;

[0026] Figure 7 This is an exemplary embodiment of the present application illustrating a model performance histogram;

[0027] Figure 8 This is an exemplary embodiment of the present application illustrating a recall histogram with a learning rate of 0.005;

[0028] Figure 9 This is an exemplary embodiment of the present application illustrating a recall histogram with a learning rate of 0.001;

[0029] Figure 10 This is an exemplary embodiment of the present application illustrating a recall histogram with a learning rate of 0.0001;

[0030] Figure 11 This is a test calculation time histogram of an interruption detection model illustrated in an exemplary embodiment of this application;

[0031] Figure 12 This is a histogram of the actual computation time of an interruption detection model illustrated in an exemplary embodiment of this application;

[0032] Figure 13 This is a schematic diagram of the structure of a routing interruption detection device shown in an exemplary embodiment of this application;

[0033] Figure 14 This is a schematic diagram of the structure of another routing interruption detection device shown in an exemplary embodiment of this application;

[0034] Figure 15 This is a hardware structure diagram of a computer device illustrated in an exemplary embodiment of this application. Detailed Implementation

[0035] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0036] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0037] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0038] The current Internet uses the Border Gateway Protocol (BGP) for inter-domain routing. BGP is a distributed protocol that requires each Autonomous System (AS) in the Internet to perform its own route selection and advertise its chosen route path to neighboring ASs. However, it does not impose any restrictions on the route selection or the route path advertised by each AS. Therefore, ASs have a high degree of autonomy in advertising paths. This increases the possibility of network failures due to misoperation, provides room for malicious network attacks, and increases the difficulty of route failure detection.

[0039] Common routing failures include AS outages, which occur when an AS suddenly fails and becomes unable to provide services. A key manifestation of an AS outage is the sudden issuance of a large number of IP prefix withdrawal messages, making these IP prefixes unreachable and consequently rendering services inaccessible. Therefore, AS outage detection is a problem worthy of study.

[0040] Specifically, the following problems typically need to be overcome during the interrupt detection process for AS:

[0041] First, due to design limitations of the BGP protocol, each AS can only receive routing information from its neighboring ASs. Therefore, based on observation points in the control plane, the information obtainable is limited; only the network state information of the locally reachable portion of the Internet near the observation point can be obtained, rather than the complete picture of the network. This means that it is impossible to obtain completely accurate results directly through precise graph theory algorithms.

[0042] Second, due to the openness of the BGP protocol, it does not restrict which routing information an AS can publish. Therefore, an AS can publish only a portion of its routing information based on its local configuration. This makes it more difficult to understand the overall network picture. Therefore, it is necessary to synthesize information from multiple ASs to make judgments and reduce the information gaps caused by the local configuration of a single AS.

[0043] Third, even with relatively complete network state information, the sheer size of the network makes executing graph theory algorithms globally prohibitively complex. Therefore, it is necessary to design a reasonable data structure to store as little critical network information as possible.

[0044] In BGP anomaly detection and interruption detection, current detection methods are mainly divided into control plane-based detection, data plane-based detection, and detection methods that combine control plane and data plane.

[0045] Control plane-based detection typically involves passively acquiring BGP (Browser General Planetary Measurement) updates, which is relatively easy to obtain and has numerous open-source datasets available, such as Route Views and RIPE RIS. However, because control plane-based detection only obtains local data from observation points, its accuracy is relatively low, potentially leading to a large number of false positives and false negatives.

[0046] Data plane detection typically requires the detector to actively send data packets into the network. Therefore, detection solely on the data plane may suffer from low detection coverage, but its accuracy is relatively high. Several open-source traceroute datasets are also available for the data plane, such as RIPE Atlas and CAIDA Ark.

[0047] Combining control plane and data plane methods is also an important detection approach. Kepler combines control plane and data plane methods when detecting internet infrastructure outages. It first detects the path change rate of the detected infrastructure on the control plane to identify potentially outage infrastructure, and then verifies the control plane detection results based on an open-source dataset from the data plane to finally identify the outage infrastructure. Fingerprints, when detecting anomalies such as route leakage and prefix hijacking, first detects multi-origin autonomous systems (MOAS) on the control plane and then verifies them on the data plane. Argus uses the correlation coefficient between data obtained from the control plane and data plane to combine the two types of data to detect BGP prefix hijacking. However, both Fingerprints and Argus detect multi-origin AS phenomena on the control plane, which can generate false positives for a large number of benign ASs, resulting in significant overhead during data plane verification.

[0048] Based on the above research, this disclosure provides a route interruption detection method. First, Border Gateway Protocol (BGP) routing data from the control plane of the network is collected through observation points; these observation points are routing data collection nodes deployed in the network. Then, based on the BGP routing data, the target Autonomous System (AS) experiencing a route change and its routing information are determined. The routing information of the target AS includes the path withdrawal ratio, the total number of paths to the target AS, the IP prefix withdrawal ratio of the target AS, the total number of IP prefixes to the target AS, the next-hop withdrawal ratio of the observation point, and the total number of next-hops to the observation point. Finally, features are extracted from the routing information of the target AS to obtain an AS routing feature vector, which is then input into an interruption detection model for interruption detection to obtain an interruption detection result. The interruption detection result indicates whether the target AS has experienced an interruption.

[0049] In this embodiment of the application, BGP routing data is automatically collected by deployed observation points. The target AS and its routing information are determined based on the BGP routing data. Model inference is then performed based on the routing information of the target AS, which can automatically detect whether the target AS has been interrupted.

[0050] Furthermore, since the routing information of the target AS includes the path withdrawal ratio of the target AS, the total number of paths of the target AS, the IP prefix withdrawal ratio of the target AS, the total number of IP prefixes of the target AS, the next-hop withdrawal ratio of the observation point, and the total number of next hops of the observation point, that is, the routing information of the target AS corresponds to both the observation point dimension and the dimension to be observed (the target AS that has changed), the information coverage is large. Thus, the detection accuracy can be improved when performing interruption detection.

[0051] To facilitate understanding of this embodiment, a detailed description of the routing interruption detection method disclosed in this disclosure is provided first. The execution entity of the routing interruption detection method provided in this disclosure is generally a computer device. This computer device can be a server, which can be an independent physical server, a server cluster composed of multiple physical servers, or a distributed system. It can also be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud storage, big data, and artificial intelligence platforms. In other embodiments, the computer device can also be a terminal device, which can be a mobile device, terminal, handheld device, computing device, vehicle-mounted device, etc.

[0052] In other embodiments, the method can also be applied to an implementation environment consisting of computer equipment and servers. Furthermore, this routing interruption detection method can also be implemented by the processor calling computer-readable instructions stored in memory.

[0053] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.

[0054] Please participate in the attached... Figure 1 The above is a flowchart illustrating a routing interruption detection method as an exemplary embodiment of this application. Figure 1 As shown, the routing interruption detection method in this embodiment may include the following steps S101 to S103:

[0055] S101: Collect Border Gateway Protocol (BGP) routing data of the control plane in the network through observation points; the observation points are routing data collection nodes deployed in the network.

[0056] Border Gateway Protocol (BGP) is a routing protocol used to exchange Network Layer Reachability Information (NLRI) between routing domains. Because different administrative bodies control their respective routing domains, these domains are often referred to as Autonomous Systems (AS). The Internet is a large network composed of interconnected autonomous systems.

[0057] The control plane is responsible for routing decisions within the network, that is, determining the path for data packets. The control plane primarily involves routing algorithms and protocols, such as OSPF and BGP. These protocols help network devices understand the overall network topology and determine data transmission paths.

[0058] In this embodiment of the application, the BGP routing data is obtained from RIPE RIS.

[0059] Here, the observation point is a routing data acquisition node deployed in the network, used to collect Border Gateway Protocol (BGP) routing data in the control plane of the network. The BGP routing data includes the RIB routing table and BGP update information.

[0060] A routing table, also known as a Routing Information Base (RIB), is a spreadsheet (file) or database-like object stored in a router or networked computer. The routing table stores paths to specific network addresses (and in some cases, routing metrics). It contains topology information about the surrounding network. The primary goal of creating a routing table is to implement routing protocols and static route selection. The routing table includes the network topology (path connections between ASs) and the IP prefixes advertised by each AS.

[0061] BGP update information is used to record dynamic information such as the addition, removal, and path changes of IP prefixes.

[0062] S102: Based on the BGP routing data, determine the target Autonomous System (AS) where the routing change has occurred and the routing information of the target AS; the routing information of the target AS includes the path withdrawal ratio of the target AS, the total number of paths of the target AS, the IP prefix withdrawal ratio of the target AS, the total number of IP prefixes of the target AS, the next-hop withdrawal ratio of the observation point, and the total number of next hops of the observation point.

[0063] Here, it can be understood that since BGP routing data is periodically updated, each update may involve updating routing information. Therefore, it is necessary to determine the target Autonomous System (AS) and its routing information based on the BGP routing data.

[0064] The total number of paths to the target AS refers to the total number of paths leading to the IP prefixes advertised by the target AS. The path withdrawal ratio of the target AS is the ratio of the number of withdrawn paths to the total number of paths to the target AS. Here, the "withdraw" message in the BGP routing data will clearly mark which path is invalid, and the withdrawal number is counted accordingly. The total number of IP prefixes to the target AS refers to the total number of all IP prefixes advertised by the target AS to the entire network through the BGP protocol. The IP prefix withdrawal ratio of the target AS is the ratio of the number of withdrawn IP prefixes to the total number of IP prefixes of the target AS. The total number of next hops to the observation point refers to the total number of directly adjacent next-hop ASs in the route from the observation point to the target AS. The next-hop withdrawal ratio of the observation point is the ratio of the number of withdrawn next hops to the target AS to the total number of next-hop ASs.

[0065] It can be seen that this application determines the above six pieces of information from the perspectives of the observation point and the target AS (the AS to be observed), thereby obtaining the routing information of the target AS, which can improve the completeness of the routing information.

[0066] In this application, a statistical analysis of the feasibility of AS interruption detection based on a large number of experiments is conducted. Please refer to [link to relevant documentation]. Figures 2-3 .

[0067] Figure 2 A histogram of AS withdrawal path percentage is provided for an exemplary embodiment of this application. Figure (a) is a histogram of withdrawal path percentage for ASs marked as interrupted, and Figure (b) is a histogram of withdrawal path percentage for ASs marked as normal (non-interrupted).

[0068] As shown in Figure (a), the proportion of pullback paths for ASs marked as interrupted is mainly distributed above 0.2, with the highest proportion between 0.6 and 0.8. As shown in Figure (b), the proportion of pullback paths for ASs marked as normal is mainly distributed below 0.3, with the highest proportion between 0.0 and 0.1. Therefore, normal ASs and interrupted ASs can be distinguished by the proportion of pullback paths.

[0069] Figure 3 A histogram of the percentage of ASs withdrawing next hops is provided for an exemplary embodiment of this application. Figure (a) is a histogram of the percentage of ASs withdrawing next hops marked as interrupted, and Figure (b) is a histogram of the percentage of ASs withdrawing next hops marked as normal (non-interrupted).

[0070] As shown in Figure (a), the percentage of next-hop withdrawals for ASs marked as interrupted is mainly distributed between 0.5 and 0.8. As shown in Figure (b), the percentage of next-hop withdrawals for ASs marked as normal has two peaks: 0.0 to 0.1 and 0.4 to 0.6. Overall, normal ASs and interrupted ASs can be distinguished by their withdrawn next-hops.

[0071] Therefore, AS interruption detection can be performed based on the withdrawal path and the next hop after withdrawal.

[0072] Optionally, when determining the target Autonomous System (AS) and its routing information based on the BGP routing data, the following steps (1) to (3) are included:

[0073] (1) Based on the RIB routing table, construct the target network topology map and record the target routing information.

[0074] As is well known, a network topology graph is a logical topology of a network represented by a graph structure, where nodes represent Autonomous Systems (AS) and edges represent the connections between ASs.

[0075] The target routing information may include prefix information, path information, and next-hop information. Specifically, the prefix information may include all prefixes declared by the target AS and the total number of all prefixes. The path information may include the total number of paths to each prefix. The next-hop information may include the number of next-hop ASs from the observation point to the target AS.

[0076] (2) Based on the BGP update information, update the target network topology map and the target routing information respectively to obtain the updated target network topology map and the updated target routing information.

[0077] As mentioned earlier, BGP update information typically includes dynamic messages such as route announcements, withdrawals, and path changes. Based on these BGP update messages, the initial topology map and routing information can be corrected, for example, by adding or deleting links. This allows for timely updates to the target network topology map and target routing information, improving their accuracy and real-time performance.

[0078] The BGP update information is updated according to a preset cycle.

[0079] (3) Determine the changed target AS based on the updated target network topology map, and determine the routing information of the target AS based on the updated target routing information.

[0080] In this step, based on the updated target network topology map, the target AS that has changed (such as newly added / disappeared AS nodes, AS with changed link status) can be accurately located, and its routing information (such as the total number of changed paths, the next hop withdrawal ratio, etc.) can be extracted.

[0081] In this implementation, BGP update information is introduced for dynamic updates, which can respond in real time to routing changes in the network (such as path withdrawal caused by AS link failure or path adjustment caused by new routing policies), ensuring that the target network topology map and the routing information of the target AS can be synchronized with the actual network status, and avoiding misjudgments caused by outdated data.

[0082] In some implementations, constructing a target network topology map based on the RIB routing table may include the following steps (A)-(B):

[0083] (A) Based on the RIB routing table, construct a prefix routing information table and an AS routing information mapping table; the prefix routing information mapping table is used to record at least one IP prefix and the set of ASs to which each IP prefix belongs, and the AS routing information mapping table is used to characterize the routing status of the AS and the IP prefix it holds.

[0084] Table 1 shows the prefix routing information mapping table. This table uses the IP prefix as the core index and records the set of ASs to which the IP prefix belongs. That is, since an IP prefix may be advertised by multiple ASs at the same time, a prefix routing information table can be constructed.

[0085] Table 1

[0086] name type describe Owner AS gather The AS set to which this prefix belongs

[0087] Parse the IP prefix and AS path information in the RIB, identify which ASs advertise each IP prefix (for example, if the AS path of a route entry is "AS100→AS200", then the IP prefix may be originally advertised by AS100 and advertised by AS200 as a relay), and generate a prefix routing information mapping table.

[0088] The AS routing information mapping table uses the target AS as its core index, recording the target AS's interruption status (e.g., interrupted or not interrupted), all IP prefixes held (or advertised) by the target AS, and their routing status (e.g., whether the route is active, whether it has been withdrawn, path stability, etc.). Its function is to integrate the routing resources and status managed by the target AS from its perspective. As shown in Table 2, the AS routing information mapping table includes the set of reachable prefixes held by the AS, the set of prefixes withdrawn by the AS, the interruption status of the AS, and the routing information of the prefixes held by the AS.

[0089] Table 2

[0090] name type describe Normal Prefixes gather The set of reachable prefixes held by AS Outaged Prefixes gather The set of prefixes that AS once held but which were subsequently revoked. Is Outaged Boolean AS interrupt status Prefixes Info Mapping Routing information of the prefix held by the AS

[0091] Furthermore, the routing information for the prefixes held by the ASs in Table 2 may specifically include the following, as shown in Table 3:

[0092] Table 3

[0093] name type describe Reachable VPs gather It is possible to reach the next hop AS of this prefix. Unreachable VPs gather The revoked next hop AS to the prefix VP Paths Mapping Record all AS paths that reach the prefix for each next hop. Withdrawn VP Paths Mapping Record the AS path that is withdrawn for each next hop to the prefix.

[0094] The routing information held by an AS for a prefix includes a set of next-hop ASs that can reach the IP prefix, a set of withdrawn next-hop ASs that can reach the prefix, a reachable path mapping table, and a withdrawn path mapping table. The reachable path mapping table records all AS paths from each next hop to the current IP prefix, and the withdrawn path mapping table records the AS paths from each next hop to the current IP prefix that have been withdrawn.

[0095] (B) Construct the target network topology based on the prefix routing information mapping table and the AS routing information mapping table.

[0096] As mentioned above, the prefix routing information mapping table reveals the "set of ASs associated with IP prefixes". These ASs form potential routing interaction relationships because they jointly advertise or transit the same prefix (e.g., AS1 and AS2 both advertise prefix P, and may have peering or transit relationships).

[0097] As mentioned earlier, the AS routing information mapping table includes the set of reachable prefixes held by the AS, the set of prefixes withdrawn by the AS, the interruption status of the AS, and the routing information of the prefixes held by the AS. By combining the correlation information of the two tables, the target network topology map can be constructed. That is, by using the "structured mapping table" as a bridge, the scattered routing data in the RIB is transformed into structured information with deep correlation between "IP prefix-AS", and finally a more accurate, information-rich, and easy-to-maintain network topology map is constructed.

[0098] In some implementations, when updating the target network topology map and the target routing information based on the BGP update information to obtain the updated target network topology map and the updated target routing information, the following may be included: (I) to (II):

[0099] (I) Identify the update event type of the BGP update information; the update event type is used to indicate the change information of the routing status of the IP prefix.

[0100] The update event types include announcement events (used to indicate the addition or modification of routes) and retraction events (used to indicate the cancellation of routes).

[0101] For example, for an announcement event: a new route for a certain IP prefix is ​​published (e.g., AS1 announces to AS2 "the 192.0.2.0 / 24 prefix is ​​reachable via AS1"), or the path information of an existing route is updated (e.g., the original path "AS1→AS2" is changed to "AS1→AS3→AS2"); for a withdrawal event: the original route for a certain IP prefix is ​​marked as unreachable (e.g., AS1 withdraws the route "192.0.2.0 / 24 prefix" from AS2, that is, the prefix is ​​deleted from the routing table of AS2).

[0102] (II) Update the target network topology map and the target routing information according to the update event type of the BGP update information to obtain the updated target network topology map and the updated target routing information.

[0103] Once the update event type (announcement event or withdrawal event) is determined, the target network topology map and target routing information can be updated respectively.

[0104] For updating the target network topology: Since the target network topology usually reflects the connection relationship between ASs and the logical association of routing paths (such as the edge in the topology corresponding to the path "AS1→AS3→AS5"), if it is an announcement event, add or adjust the path in the topology. For example, if AS2 announces a route to AS4 for the first time, then the logical edge "AS2-AS4" is added to the target network topology. If it is a "withdrawal event", delete the corresponding path in the target network topology. For example, if AS3 withdraws the route to AS5, then the edge "AS3-AS5" is removed from the target network topology.

[0105] Updates to target routing information: Since target routing information records reachability details of IP prefixes (such as the AS to which the prefix belongs, the next-hop AS, path length, etc.). If it's an announcement event: add a routing entry for the prefix (e.g., record that the next hop for "198.51.100.0 / 24" is AS6), or modify the path information of an existing entry (e.g., change the next hop from AS6 to AS7); if it's a withdrawal event: delete the routing entry for the corresponding prefix (e.g., remove all records for "198.51.100.0 / 24" from the routing table).

[0106] Therefore, when updating the target IP prefix in the BGP update information, if it is an announcement event (which can be understood as the AS adding / updating reachable routes for the target IP prefix), it is necessary to add the target IP prefix to the prefix routing information table, add the target IP prefix to the set of reachable prefixes held by the target AS in the AS routing information mapping table, and update the set of reachable next-hop ASs and the reachable path mapping table in the routing information of the prefixes held by the target AS.

[0107] Similarly, when updating target routing information, if it is a revocation event (which can be understood as the AS removing the reachable route of the target IP prefix), then it is necessary to remove the target IP prefix from the prefix routing information table, remove the target IP prefix from the reachable prefix set held by the target AS, add the target IP prefix to the target AS's revoked prefix set in the AS routing information mapping table, and update the prefix routing information of the AS.

[0108] S103: Extract features from the routing information of the target AS to obtain an AS routing feature vector, and input the AS routing feature vector into the interruption detection model for interruption detection to obtain an interruption detection result; the interruption detection result is used to indicate whether the target AS has been interrupted.

[0109] The interruption detection model is a logistic regression model.

[0110] It is understandable that after obtaining the routing information of the target AS, the above information can be used to generate an AS routing feature vector according to a fixed dimension, and the AS routing feature vector can be input into the interruption detection model to perform interruption detection and obtain the interruption detection result.

[0111] Here, the interruption detection model's detection process is actually a binary classification. The interruption detection result it obtains includes the interruption probability of the target AS. The interruption probability refers to the probability that the target AS will be interrupted, indicating whether the target AS has been interrupted.

[0112] In the specific implementation process, a probability threshold can be set in advance. If the interruption probability is greater than the probability threshold, it is determined that the target AS has been interrupted. If the interruption probability is less than the probability threshold, it is determined that the target AS has not been interrupted.

[0113] In this embodiment, by determining the target AS that has undergone a route change and its routing information, including the path withdrawal ratio of the target AS, the total number of paths of the target AS, the IP prefix withdrawal ratio of the target AS, the total number of IP prefixes of the target AS, the next-hop withdrawal ratio of the observation point, and the total number of next hops of the observation point, AS routing vector features are generated based on the routing information of the target AS. That is, AS routing vector features are generated from the dimensions of the observation point and the target AS, which can improve the accuracy of interruption detection.

[0114] In this application, the intermediate detection model is obtained through supervised training based on training sample data, which is generated in the following way:

[0115] (a) Obtain historical AS interruption information and historical BGP routing data corresponding to the historical AS interruption information.

[0116] The historical AS interruption information is used to characterize whether the historical AS was interrupted.

[0117] Here, historical AS outage information refers to AS outage information within a historical time period, and historical BGP routing data refers to BGP routing data corresponding to historical AS outage information within a historical time period.

[0118] Optionally, when obtaining historical AS interruption information and the historical BGP routing data corresponding to the historical AS interruption information, the historical AS interruption information can be obtained first. The historical AS interruption information includes the historical AS number, interruption start time, and interruption end time. Then, the historical AS interruption information is grouped according to the historical AS number to obtain the interruption time interval of each historical AS. Based on the interruption time interval of each historical AS, the historical BGP routing data within the interruption time interval is obtained.

[0119] Here, the historical outage information clearly records the specific time range during which the AS corresponding to the historical AS number experienced an outage. Since the outages of different ASs are independent of each other, grouping by historical AS number allows for precise location of a specific historical AS. For example, the outage of AS1 from March 1st to 2nd, 2023, and the outage of AS2 from May 1st to 2nd, 2023, will be grouped into AS1 and AS2 groups respectively. BGP routing data within the outage time interval can then be extracted: BGP (Border Gateway Protocol) is the core protocol for exchanging routing information between ASs, and its routing data (such as route announcements, withdrawals, path changes, etc.) directly reflects the routing status of the AS. By filtering by "outage time interval," the BGP routing data of the AS at the time of the outage can be extracted. For example, during the outage of AS1 from March 1st to 2nd, 2023, were there numerous route withdrawals, route unreachability, or abnormally increased path hop counts?

[0120] In this embodiment, historical AS outage information can be obtained from the Cisco Crosswork BGPStream, and the historical BGP routing data corresponding to the historical AS outage information can be obtained from RIPE RIS. RIPE RIS publishes the RIB table every 8 hours and BGP update information every 5 minutes.

[0121] Please refer to Table 4, which shows the CISCO Crosswork BGPStream information format.

[0122] Table 4

[0123] item describe Event type Event Type Country Region ASN AS number Start time (UTC) Event start time End time (UTC) Event End Time

[0124] Here, event types can include interrupt types, prefix hijacking types, etc.

[0125] (b) Generate the training sample data based on the historical BGP routing data, and use the historical AS interruption information as the label of the interruption training sample.

[0126] Here, the interruption detection model requires labeled data (i.e., "routing features during interruption" as positive samples and "routing features during normal operation" as negative samples). Using the method described above, "BGP data within the interruption time interval" can be directly labeled as "interruption samples," and BGP data outside of interruption times can be labeled as "normal samples," providing accurate feature vectors and labels for model training and improving the model's detection accuracy.

[0127] It should be noted that when generating the training sample data based on the historical BGP routing data, the target historical Autonomous System (AS) and its routing information can be determined first based on the historical BGP routing data. The routing information of the target historical AS includes the path withdrawal ratio, the total number of paths of the target historical AS, the IP prefix withdrawal ratio, the total number of IP prefixes of the target historical AS, the next-hop withdrawal ratio of the historical observation point, and the total number of next-hops of the historical observation point. The training sample data is then generated based on the routing information of the target historical AS.

[0128] Among them, historical BGP data refers to BGP routing data collected by observation points within a historical time period. Here, the next-hop withdrawal ratio of historical observation points refers to the next-hop withdrawal ratio of observation points within a historical time period, and the total number of next-hops of historical observation points refers to the total number of next-hops of observation points within a historical time period.

[0129] Furthermore, the specific implementation process of determining the target historical autonomous system (AS) and its routing information based on historical BGP routing data is similar to the content of "S102: Determine the target autonomous system (AS) and its routing information based on the BGP routing data" in the aforementioned embodiment, and will not be repeated here.

[0130] Please see Figure 4 This is a flowchart illustrating an interruption detection method provided in an exemplary embodiment. Figure 4As shown, the flowchart is divided into training process 10 and detection process 20. First, for training process 10, historical BGP routing data (including historical RIB routing tables and BGP update information) is collected from RIPE RIS, and historical outage information is obtained from CISCO CrossworkBGPStream. Based on the historical RIB routing tables, a historical network topology map and historical routing information are constructed, and the historical network topology map is updated based on the BGP update information. The historical target AS that has changed and its routing information are determined. Training samples are generated based on the routing information of the historical target AS, and the historical outage information is used as the label of the training samples. Then, the logistic regression model is trained in a supervised manner to obtain the outage detection model.

[0131] For detection process 20, BGP routing data (including RIB routing table and BGP update information) is obtained from RIPE RIS in real time. The target network topology map is constructed based on the RIB routing table, and the target routing information is determined. Then, the target network topology map and target routing information are updated based on the BGP update information to determine the target AS where the change occurred and the routing information of the target AS. The target AS feature vector is generated based on the routing information of the target AS and input into the interruption detection model to obtain the interruption detection result.

[0132] In some implementations, after obtaining the interruption detection model, the model can be further evaluated. Specifically, a test dataset can be constructed to evaluate the model. In this application, when constructing the test set, BGP data can be selected as the test set in chronological order. Specifically, an equal amount of BGP data for normal AS and interruption AS can be randomly selected from the data in the first 80% of the time period as the training set, and a certain amount of BGP data can be randomly selected from the BGP data in the last 20% of the time period as the test set. Please refer to [link to relevant documentation]. Figure 5 This is a training set and test set size distribution diagram provided as an exemplary embodiment of this application, such as... Figure 5 As shown, the blue histogram represents the number of BGP data points for normal AS, and the red histogram represents the number of BGP data points for interrupted AS. In the training set, the number of BGP data points for normal AS and interrupted AS is the same, while in the test set, the number of BGP data points for normal AS is greater than that for interrupted AS.

[0133] In specific implementation, the interruption detection model (logistic regression model) of this application can use a linear fully connected layer with a model size of 6*32, a Dropout layer with a connection parameter of 0.1, and a logistic regression output layer. The optimizer uses the Adam optimizer with a learning rate of 0.001 and a weight decay coefficient of 0.0001.

[0134] Please see Figure 6 This is a detection result histogram provided as an exemplary embodiment of this application. Figure 7 A model performance histogram is provided for an exemplary embodiment of this application.

[0135] like Figure 6 As shown, for the training set, the number of samples where a normal AS was detected as normal is approximately 5.9 * 10-1. 4 The number of samples where the interrupted AS was detected as being in an interrupted state is approximately 9*10. 4 For the test set, the number of samples where normal AS was detected as normal is approximately 0.3 * 10^6. 4 The number of samples where the interrupted AS was detected as being in an interrupted state is approximately 4.3 * 10^3. 4 .

[0136] like Figure 7 As shown, the recall rate of the interruption detection model is approximately 92.29%.

[0137] Of the 49,602 samples with interruptions detected by the CISCO Crosswork BGPStream, the model detected 45,776 samples, resulting in a detection rate (recall rate) of 92.29%.

[0138] Furthermore, this application also explored the impact of the learning rate and linear layer size on the detection results. Specifically, experiments were conducted using a weight decrease of 0.0001 and a dropout of 0.1 to find the optimal linear layer size and learning rate. Since the optimal learning rate of the model is related to the linear layer size, orthogonal experiments were performed using different learning rates and different linear layer sizes. We investigated the detection performance of models with linear layer sizes of 4, 8, 16, 32, 64, 128, and 256, respectively, under learning rates of 0.005, 0.001, and 0.0001.

[0139] Please see Figure 8-10 These are histograms of recall rates under different learning rates provided in the embodiments of this application.

[0140] like Figure 8-10 As shown, when the learning rate is 0.005 and the linear layer size is 4 or 32 or larger, and when the learning rate is 0.001 or 0.0001 and the linear layer size is 4, the recall rate is 0 or 1. This indicates that when the linear layer size is 4, the model's representational power is too low to classify AS correctly. Conversely, when the learning rate is too high, larger models struggle to find the correct optimal solution.

[0141] Furthermore, this application also verifies the real-time performance of the method. Since the RIPE RIS dataset publishes BGP updates every 5 minutes, to ensure real-time monitoring, the processing of data generated by each update and interruption detection must be completed within 5 minutes. Therefore, we statistically analyzed the time required for detection.

[0142] The time consumption for interruption detection mainly lies in data processing and model computation. Since only BGP retraction messages cause interruptions, we only generate AS feature vectors for BGP retraction messages. We randomly selected five BGP update information files as data samples to test the time for calculating the input model's feature vectors and the model's computation time. Figure 11 As shown, Figure 11 The number of prefix retraction messages in each update information file and the time required to calculate the feature vector of the input model based on the retraction messages in each update information file are displayed. Figure 12 The graph shows the computation time of the model after each feature vector is input into the model. As can be seen from the statistical chart, the feature vector calculation and model computation for the five extracted update information samples can be completed within seconds, yielding a determination of whether an interruption has occurred. Interruption detection can be completed within the 5-minute release interval of BGP update information. Therefore, the interruption detection method of this application can meet the minute-level real-time requirement.

[0143] Corresponding to the embodiments of the aforementioned route interruption detection method, this application also provides embodiments of a route interruption detection device.

[0144] Please refer to Figure 13 This is a schematic diagram illustrating the structure of a route interruption detection device according to an exemplary embodiment of this application. Figure 13 As shown, the routing interruption detection device 1300 includes:

[0145] The acquisition module 1310 is used to acquire Border Gateway Protocol (BGP) routing data of the control plane in the network through observation points; the observation points are routing data acquisition nodes deployed in the network.

[0146] The determination module 1320 is used to determine the target Autonomous System (AS) that has undergone a route change and the routing information of the target AS based on the BGP routing data; the routing information of the target AS includes the path withdrawal ratio of the target AS, the total number of paths of the target AS, the IP prefix withdrawal ratio of the target AS, the total number of IP prefixes of the target AS, the next-hop withdrawal ratio of the observation point, and the total number of next hops of the observation point.

[0147] The detection module 1330 is used to extract features from the routing information of the target AS to obtain an AS routing feature vector, and input the AS routing feature vector into the interruption detection model to perform interruption detection and obtain an interruption detection result; the interruption detection result is used to indicate whether the target AS has been interrupted.

[0148] In some implementations, the BGP routing data includes a RIB routing table and BGP update information; the determining module 1320 is specifically used for:

[0149] Based on the RIB routing table, construct the target network topology map and record the target routing information;

[0150] Based on the BGP update information, the target network topology map and the target routing information are updated respectively to obtain the updated target network topology map and the updated target routing information.

[0151] The target AS that has changed is determined based on the updated target network topology map, and the routing information of the target AS is determined based on the updated target routing information.

[0152] In some embodiments, the determining module 1320 is specifically used for:

[0153] Based on the RIB routing table, a prefix routing information table and an AS routing information mapping table are constructed; the prefix routing information mapping table is used to record at least one IP prefix and the set of ASs to which each IP prefix belongs, and the AS routing information mapping table is used to characterize the routing status of the target AS and the IP prefix it holds.

[0154] The target network topology is constructed based on the prefix routing information mapping table and the AS routing information mapping table.

[0155] In some implementations, the AS routing information mapping table includes the set of reachable prefixes held by the target AS, the set of prefixes withdrawn by the target AS, the interruption status of the target AS, and the routing information mapping relationship of the prefixes held by the target AS.

[0156] The routing information mapping relationship of the prefix held by the target AS includes the set of next-hop ASs reaching the target IP prefix, the set of next-hop ASs that have been withdrawn from reaching the target IP prefix, the reachable path mapping relationship table, and the withdrawn path mapping relationship table. The reachable path mapping relationship table is used to record all AS paths from each next hop to the target IP prefix, and the withdrawn path mapping relationship table is used to record the AS paths from each next hop to the target IP prefix that have been withdrawn.

[0157] In some embodiments, the determining module 1320 is specifically used for:

[0158] Identify the update event type of the BGP update information; the update event type is used to indicate changes in the routing status of the IP prefix;

[0159] Based on the update event type of the BGP update information, the target network topology map and the target routing information are updated respectively to obtain the updated target network topology map and the updated target routing information.

[0160] In some implementations, the BGP update information includes a target IP prefix, and the update event type includes an announcement event, which is used to indicate a new AS path leading to the target IP prefix; the determining module 1320 is specifically used for:

[0161] In the target network topology map, the reachable next-hop AS of the target IP prefix is ​​added to obtain the updated target network topology map; and

[0162] The newly added target IP prefix is ​​added to the prefix routing information table, the IP prefix is ​​added to the set of reachable prefixes held by the target AS, the set of next-hop ASs that can reach the target IP prefix is ​​updated, and the reachable path mapping table is updated to obtain the updated target routing information.

[0163] In some implementations, the BGP update information includes a target IP prefix, and the update event type includes a withdrawal event, which indicates withdrawal to the AS path reaching the target IP prefix; the determining module 1320 is specifically used for:

[0164] In the target network topology graph, the reachable next-hop AS of the target IP prefix is ​​deleted to obtain the updated target network topology graph; and

[0165] The target IP prefix is ​​removed from the prefix routing information table, the target IP prefix is ​​removed from the reachable prefix set held by the target AS, the target IP prefix is ​​added to the next-hop AS set of the withdrawn IP prefix, and the reachable path mapping table and the withdrawn path mapping table are updated to obtain the updated target routing information.

[0166] Please see Figure 14 This is a schematic diagram of another routing interruption detection device provided in an exemplary embodiment of this application. Figure 14As shown, the routing interruption detection device 1300 further includes a sample generation module 1340. The interruption detection model is obtained through supervised training based on training sample data. The sample generation module 1340 is used for:

[0167] Obtain historical AS interruption information and corresponding historical BGP routing data; the historical AS interruption information is used to indicate whether the historical AS was interrupted.

[0168] The training sample data is generated based on the historical BGP routing data, and the historical AS interruption information is used as the label for the interruption training sample.

[0169] The sample generation module 1340 is specifically used for:

[0170] Obtain the historical AS interruption information; the historical AS interruption information includes the historical AS number, interruption start time, and interruption end time.

[0171] The historical AS interruption information is grouped according to the historical AS number to obtain the interruption time interval of each historical AS. Based on the interruption time interval of each historical AS, the historical BGP routing data within the interruption time interval is obtained.

[0172] The specific implementation process of the functions and roles of each unit in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0173] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0174] Corresponding to the above-described routing interruption detection method, this disclosure also provides a computer device, such as... Figure 15 The diagram shown is a structural schematic of a computer device provided in an embodiment of this disclosure, including:

[0175] Computer device 1500 includes a processor 1510, an internal bus 1520, memory 1530, a network interface 1540, and non-volatile memory 1550, and may also include other hardware required for its functions. One or more embodiments of this specification can be implemented in software, for example, the processor 1510 reads the corresponding computer program from the non-volatile memory 1550 into the memory 1530 and then runs it. Of course, besides software implementation, one or more embodiments of this specification do not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. That is to say, the execution entity of the following processing flow is not limited to individual logic units, but can also be hardware or logic devices.

[0176] The memory 1530, also known as internal memory, is used to temporarily store the computational data in the processor 1510, as well as the data exchanged with non-volatile memory 1550 such as hard disk. The processor 1510 exchanges data with non-volatile memory 1550 through the memory 1530.

[0177] In this embodiment, memory 1530 is specifically used to store application code that executes the solution of this application, and its execution is controlled by processor 1510. That is, when the computer device is running, processor 1510 communicates with network interface 1540, memory 1530 and non-volatile memory 1550 through internal bus 1520, so that processor 1510 executes the application code stored in memory 1530 and non-volatile memory 1550, thereby executing the routing interruption detection method described in the above method embodiment.

[0178] Processor 1510 may be an integrated circuit chip with signal processing capabilities. The aforementioned processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor or any conventional processor.

[0179] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the computer device 1500. In other embodiments of this application, the computer device 1500 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0180] This disclosure also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the routing interruption detection method described in the above-described method embodiments. The storage medium can be a volatile or non-volatile computer-readable storage medium.

[0181] This disclosure also provides a computer program product carrying program code. The program code includes instructions that can be used to execute the steps of the routing interruption detection method in the above method embodiments. For details, please refer to the above method embodiments, which will not be repeated here.

[0182] The aforementioned computer program product can be implemented through hardware, software, or a combination thereof. In one optional embodiment, the computer program product is specifically embodied in a computer storage medium; in another optional embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.

[0183] The embodiments of the subject matter and functional operation described in this specification can be implemented in the following ways: digital electronic circuits, tangibly embodied computer software or firmware, computer hardware including the structures disclosed in this specification and their structural equivalents, or combinations thereof. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on a tangible, non-transitory program carrier for execution by a data processing apparatus or for controlling the operation of a data processing apparatus. Alternatively or additionally, the program instructions may be encoded on artificially generated propagation signals, such as machine-generated electrical, optical, or electromagnetic signals, which are generated to encode information and transmit it to a suitable receiving device for execution by the data processing apparatus. The computer storage medium may be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or combinations thereof.

[0184] The processing and logic flow described in this specification can be executed by one or more programmable computers that execute one or more computer programs to perform corresponding functions by operating on input data and generating output. The processing and logic flow can also be executed by dedicated logic circuitry—such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits), and the device can also be implemented as dedicated logic circuitry.

[0185] Suitable computers for executing computer programs include, for example, general-purpose and / or special-purpose microprocessors, or any other type of central processing unit. Typically, the central processing unit receives instructions and data from read-only memory and / or random access memory. The basic components of a computer include a central processing unit for implementing or executing instructions and one or more memory devices for storing instructions and data. Typically, a computer will also include one or more mass storage devices for storing data, such as disks, magneto-optical disks, or optical disks, or the computer will be operatively coupled to such mass storage devices to receive data from or transfer data to them, or both. However, a computer is not required to have such devices. Furthermore, a computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device such as a universal serial bus (USB) flash drive, to name a few.

[0186] Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, such as semiconductor memory devices (e.g., EPROM, EEPROM, and flash memory devices), magnetic disks (e.g., internal hard disks or removable disks), magneto-optical disks, and CD-ROM and DVD-ROM disks. Processors and memory may be supplemented by or incorporated into dedicated logic circuitry.

[0187] While this specification contains numerous specific implementation details, these should not be construed as limiting the scope of any invention or the scope of the claims, but rather are primarily intended to describe features of specific embodiments of a particular invention. Certain features described in the various embodiments herein may also be implemented in combination in a single embodiment. Conversely, various features described in a single embodiment may also be implemented separately in various embodiments or in any suitable sub-combination. Furthermore, while features may function in certain combinations as described above and even initially claimed in this way, one or more features from a claimed combination may be removed from that combination in some cases, and a claimed combination may refer to a sub-combination or a variation thereof.

[0188] Similarly, although the operations are depicted in a specific order in the accompanying drawings, this should not be construed as requiring these operations to be performed in the specific order shown or sequentially, or requiring all illustrated operations to be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Furthermore, the separation of various system modules and components in the above embodiments should not be construed as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.

[0189] Thus, specific embodiments of the subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims may be performed in a different order and still achieve the desired result. Furthermore, the processes depicted in the drawings are not necessarily shown in a specific order or sequence to achieve the desired result. In some implementations, multitasking and parallel processing may be advantageous.

[0190] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for detecting routing interruptions, characterized in that, include: Boundary Gateway Protocol (BGP) routing data in the control plane of the network is collected through observation points; The observation point is a routing data acquisition node deployed in the network; Based on the BGP routing data, the target Autonomous System (AS) that has undergone the routing change and the routing information of the target AS are determined. The routing information of the target AS includes the path withdrawal ratio of the target AS, the total number of paths of the target AS, the IP prefix withdrawal ratio of the target AS, the total number of IP prefixes of the target AS, the next-hop withdrawal ratio of the observation point, and the total number of next hops of the observation point. The routing information of the target AS is used to extract features to obtain an AS routing feature vector, and the AS routing feature vector is input into an interruption detection model to perform interruption detection and obtain an interruption detection result; the interruption detection result is used to indicate whether the target AS has been interrupted.

2. The method according to claim 1, characterized in that, The BGP routing data includes the RIB routing table and BGP update information; The step of determining the target Autonomous System (AS) undergoing route change and its routing information based on the BGP routing data includes: Based on the RIB routing table, construct the target network topology map and record the target routing information; Based on the BGP update information, the target network topology map and the target routing information are updated respectively to obtain the updated target network topology map and the updated target routing information. The target AS that has changed is determined based on the updated target network topology map, and the routing information of the target AS is determined based on the updated target routing information.

3. The method according to claim 2, characterized in that, The construction of the target network topology map based on the RIB routing table includes: Based on the RIB routing table, a prefix routing information table and an AS routing information mapping table are constructed; the prefix routing information mapping table is used to record at least one IP prefix and the set of ASs to which each IP prefix belongs, and the AS routing information mapping table is used to characterize the routing status of the target AS and the IP prefix it holds. The target network topology is constructed based on the prefix routing information mapping table and the AS routing information mapping table.

4. The method according to claim 3, characterized in that, The AS routing information mapping table includes the set of reachable prefixes held by the target AS, the set of prefixes withdrawn by the target AS, the interruption status of the target AS, and the routing information mapping relationship of the prefixes held by the target AS. The routing information mapping relationship of the prefix held by the target AS includes the set of next-hop ASs reaching the target IP prefix, the set of next-hop ASs that have been withdrawn from reaching the target IP prefix, the reachable path mapping relationship table, and the withdrawn path mapping relationship table. The reachable path mapping relationship table is used to record all AS paths from each next hop to the target IP prefix, and the withdrawn path mapping relationship table is used to record the AS paths from each next hop to the target IP prefix that have been withdrawn.

5. The method according to claim 4, characterized in that, The step of updating the target network topology map and the target routing information based on the BGP update information to obtain the updated target network topology map and the updated target routing information includes: Identify the update event type of the BGP update information; the update event type is used to indicate changes in the routing status of the IP prefix; Based on the update event type of the BGP update information, the target network topology map and the target routing information are updated respectively to obtain the updated target network topology map and the updated target routing information.

6. The method according to claim 5, characterized in that, The BGP update information includes a target IP prefix, and the update event type includes an announcement event, which indicates the addition of an AS path to the target IP prefix; the step of updating the target network topology and the target routing information according to the update event type of the BGP update information to obtain the updated target network topology and updated target routing information includes: In the target network topology map, the reachable next-hop AS of the target IP prefix is ​​added to obtain the updated target network topology map; and The newly added target IP prefix is ​​added to the prefix routing information table, the IP prefix is ​​added to the set of reachable prefixes held by the target AS, the set of next-hop ASs that can reach the target IP prefix is ​​updated, and the reachable path mapping table is updated to obtain the updated target routing information.

7. The method according to claim 5, characterized in that, The BGP update information includes a target IP prefix, and the update event type includes a withdrawal event, which indicates withdrawal to the AS path reaching the target IP prefix; the step of updating the target network topology and the target routing information according to the update event type of the BGP update information to obtain the updated target network topology and updated target routing information includes: In the target network topology graph, the reachable next-hop AS of the target IP prefix is ​​deleted to obtain the updated target network topology graph; and The target IP prefix is ​​removed from the prefix routing information table, the target IP prefix is ​​removed from the reachable prefix set held by the target AS, the target IP prefix is ​​added to the next-hop AS set of the withdrawn IP prefix, and the reachable path mapping table and the withdrawn path mapping table are updated to obtain the updated target routing information.

8. The method according to any one of claims 1-7, characterized in that, The interruption detection model is obtained through supervised training based on training sample data, which is generated in the following way: Obtain historical AS interruption information and corresponding historical BGP routing data; the historical AS interruption information is used to indicate whether the historical AS was interrupted. The training sample data is generated based on the historical BGP routing data, and the historical AS interruption information is used as the label for the interruption training sample.

9. The method according to claim 8, characterized in that, The acquisition of historical AS interruption information and corresponding historical BGP routing data includes: Obtain the historical AS interruption information; the historical AS interruption information includes the historical AS number, interruption start time, and interruption end time. The historical AS interruption information is grouped according to the historical AS number to obtain the interruption time interval of each historical AS. Based on the interruption time interval of each historical AS, the historical BGP routing data within the interruption time interval is obtained.

10. A routing interruption detection device, characterized in that, include: The acquisition module is used to collect Border Gateway Protocol (BGP) routing data from the control plane of the network through observation points; The observation point is a routing data acquisition node deployed in the network; The determination module is used to determine the target Autonomous System (AS) that has undergone a route change and the routing information of the target AS based on the BGP routing data. The routing information of the target AS includes the path withdrawal ratio of the target AS, the total number of paths of the target AS, the IP prefix withdrawal ratio of the target AS, the total number of IP prefixes of the target AS, the next-hop withdrawal ratio of the observation point, and the total number of next hops of the observation point. The detection module is used to extract features from the routing information of the target AS to obtain an AS routing feature vector, and input the AS routing feature vector into the interruption detection model to perform interruption detection and obtain an interruption detection result; the interruption detection result is used to indicate whether the target AS has been interrupted.

11. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the routing interruption detection method according to any one of claims 1-9.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the routing interruption detection method according to any one of claims 1-9.