Dynamic topology processing method and system for network connection

By acquiring and aggregating the network connections of resource nodes and generating dynamic topology, the problem of failure analysis caused by the complex network environment of large banks and enterprises is solved, unified monitoring and management is realized, and operation and maintenance efficiency and fault location speed are improved.

CN115801588BActive Publication Date: 2025-08-15PING AN BANK CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211399290.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-09
Publication Date
2025-08-15
Estimated Expiration
2042-11-09

AI Technical Summary

Technical Problem

Due to historical reasons, large banking enterprises have complex network environments, numerous software architectures, and complex call chains, which leads to the inability to quickly and accurately analyze the source of failures when dealing with production failures, the inaccurate understanding of the upstream and downstream relationships of the application, the basic resources and databases they depend on, and the existing technology cannot achieve unified management and permission control.

Method used

By obtaining the network connection of resource nodes, using the resource model in CMDB for matching and aggregation, a dynamic network topology between the application and the resource node is generated, and unified monitoring and management is carried out in conjunction with the topology platform, including acquisition modules, matching modules, aggregation modules and generation modules, to demonstrate the relationship between the application and the resource nodes.

Benefits of technology

It realizes unified monitoring and management of the relationship between the application and resource nodes, can quickly locate the fault source, avoid misoperation, comply with the principle of minimum authorization, and improves operation and maintenance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801588B_ABST
    Figure CN115801588B_ABST
Patent Text Reader

Abstract

The present application provides a method for processing the dynamic topology of network connections, including: obtaining the network connection status of several resource nodes, wherein the network connection status is the access time and number of accesses between the access source and the access target, wherein the access source and the access target are the resource node that issues the access request and the resource node that responds to the access request, respectively; matching the network connection status of several received resource nodes according to the preset resource model in the CMDB to obtain a matching relationship; aggregating the matching relationships related to the same application to obtain the association relationship between the same application and the resource node; and importing the association relationship into a graph library to generate a dynamic network topology between each application and the resource node. The technical solution of the present application can analyze network connections more conveniently and intelligently.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of financial technology, and in particular to a method for dynamic topology processing of network connections and a system for dynamic topology processing of network connections. Background Art

[0002] Due to historical reasons, large banks often have complex network environments, numerous software architectures, and intricate call chains. As a result, when handling production failures, they are unable to quickly and accurately analyze the source of the failure, and are unable to accurately understand the upstream and downstream relationships of the application, the dependent basic resources, and the databases.

[0003] The bank's software architecture, application development languages, and communication protocols are diverse. It is not possible to simply use a single open source product to collect data from the entire bank's applications, and it is impossible to analyze the relationships between all applications. If multiple open source products are used for collection, the data will be distributed across various systems and cannot be used in combination for unified management.

[0004] For application operation and maintenance personnel, it is impossible to accurately control their operating permissions and scope based only on the application and infrastructure owners without an accurate network topology, which does not comply with the principle of least authorization. Summary of the Invention

[0005] In view of this, it is necessary to provide a more convenient and intelligent dynamic topology processing method and system for network connections.

[0006] In a first aspect, an embodiment of the present application provides a method for processing a dynamic topology of a network connection, the method comprising the following steps:

[0007] Obtaining network connection status of several resource nodes, wherein the network connection status is the access time and access count between an access source and an access target, and the access source and the access target are the resource nodes that issue access requests and the resource nodes that respond to the access requests, respectively;

[0008] The network connection status of several received resource nodes is matched according to the preset resource model in the CMDB to obtain a matching relationship;

[0009] Aggregate the matching relationships related to the same application to obtain the association relationship between the same application and resource nodes;

[0010] The association relationship is imported into a graph library to generate a dynamic network topology between each application and the resource node.

[0011] In a second aspect, an embodiment of the present application provides a computer device, the computer device comprising the following steps:

[0012] a computer-readable storage medium for storing program instructions; and

[0013] The program instructions are processed and executed to implement any one of the above methods for processing dynamic topology of network connections.

[0014] In a third aspect, an embodiment of the present application provides a system for processing a dynamic topology of a network connection, the system comprising:

[0015] A plurality of resource nodes, each resource node including a collection component for collecting network connection status of each resource node, wherein the network connection status is access time and access count between an access source and an access target, wherein the access source and the access target are resource nodes that issue access requests and resource nodes that respond to the access requests, respectively;

[0016] CMDB, used to store preset resource models;

[0017] The topology platform includes an acquisition module, a matching module, an aggregation module, and a generation module. The acquisition module is used to receive the network connection status of several resource nodes reported by the acquisition component. The matching module is used to match the received network connection status of the several resource nodes according to the preset resource model in the CMDB to obtain a matching relationship. The aggregation module is used to aggregate the matching relationships related to the same application to obtain the association relationship between the same application and the resource node; the generation module is used to put the association relationship into the library to generate the network dynamic topology between each application and the resource node.

[0018] The above-mentioned dynamic topology processing method and system for processing network connections can more conveniently monitor and manage the relationship between applications and resource nodes in a unified manner by generating a dynamic topology based on the access relationship between applications and resource nodes for display. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying any creative work.

[0020] Figure 1 A flowchart of a method for dynamic topology processing of network connections provided in an embodiment of the present application.

[0021] Figure 2 This is a first sub-flowchart of the method for dynamic topology processing of network connections provided in an embodiment of the present application.

[0022] Figure 3 This is a second sub-flowchart of the method for dynamic topology processing of network connections provided in an embodiment of the present application.

[0023] Figure 4 This is the third sub-flowchart of the dynamic topology processing method for network connections provided in an embodiment of the present application.

[0024] Figure 5 This is the fourth sub-flowchart of the dynamic topology processing method for network connections provided in an embodiment of the present application.

[0025] Figure 6 This is the fifth sub-flowchart of the dynamic topology processing method for network connections provided in an embodiment of the present application.

[0026] Figure 7 This is the sixth sub-flowchart of the method for dynamic topology processing of network connections provided in an embodiment of the present application.

[0027] Figure 8 A schematic diagram of the internal structure of a computer device provided in an embodiment of the present application.

[0028] Figure 9 A schematic diagram of a dynamic topology processing system for network connections provided in an embodiment of the present application.

[0029] The realization of the objectives, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0030] In order to make the purpose, technical solutions and advantages of this application more clear, the present application is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0031] The terms "first," "second," "third," "fourth," and the like (if any) in the specification and claims of this application and in the accompanying drawings are used to distinguish similar program objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate. In other words, the described embodiments are implemented according to an order other than that illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, may also encompass other content. For example, a process, method, system, product, or apparatus comprising a series of steps or units need not be limited to only those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or apparatus.

[0032] It should be noted that the descriptions of "first", "second", etc. in this application are for descriptive purposes only and should not be understood as indicating or implying their relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" or "second" may explicitly or implicitly include one or more of the features. In addition, the technical solutions between the various embodiments can be combined with each other, but this must be based on the fact that ordinary technicians in this field can implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such a combination of technical solutions does not exist and is not within the scope of protection required by this application.

[0033] Please refer to Figure 1 and Figure 9 , Figure 1 It is a flowchart of the dynamic topology processing method of network connections provided in an embodiment of the present application. Figure 9 This is a schematic diagram of a dynamic topology processing system for network connections provided in an embodiment of the present application. The dynamic topology processing system 1 for network connections specifically includes several resource nodes 2, a CMDB 3, and a topology platform 4. Each of the several resource nodes 2 includes a collection component 5, which is used to collect the network connection status of each resource node 2. The network connection status includes the access time and number of accesses between the access source and the access target, where the access source and the access target are the resource node 2 that issued the access request and the resource node 2 that responded to the access request, respectively. The resource node 2 can be a server, database, load balancing device, etc. The CMDB 3 is used to store preset resource models. The topology platform 4 includes an acquisition module 41, a matching module 42, an aggregation module 43, and a generation module 44. The acquisition module 41 is used to receive the network connection status of several resource nodes 2 reported by the collection component 5. The matching module 42 is used to match the received network connection status of the several resource nodes 2 against the preset resource models in the CMDB 3 to obtain matching relationships. The aggregation module 43 is used to aggregate matching relationships related to the same application to obtain an association relationship between the same application and the resource node 2. The generating module 44 is used to put the association relationship into a library to generate a dynamic network topology between each application and the resource node 2. The dynamic topology processing method of the network connection specifically includes the following steps S102-S108.

[0034] Step S102 obtains the network connectivity status of several resource nodes 2. The network connectivity status refers to the access time and access count between the access source and the access target, where the access source and the access target are the resource node 2 that issues the access request and the resource node 2 that responds to the access request, respectively. It is understood that each resource node 2 includes a collection component 5. Each resource node 2 uses the collection component 5 within each resource node 2 to collect the access time and access count, as well as the accessed time and access count of each resource node 2. Each resource node 2 periodically uploads the network connectivity status generated from the collected access time and access count, as well as the accessed time and access count, to the configuration management database (CMDB) within the topology platform 4.

[0035] In step S104, the network connection information of the received resource nodes 2 is matched against the preset resource models in the CMDB 3 to obtain a matching relationship. It is understood that the preset resource models in the CMDB 3 are the resource nodes 2 existing in the CMDB 3. After the topology platform 4 receives the network connection information uploaded by the acquisition component 5 in each resource node 2, the topology platform 4 matches the resource nodes 2 in each uploaded network connection information to obtain a matching relationship. The specific matching process is described in detail below.

[0036] In step S106, the matching relationships related to the same application are aggregated to obtain an association relationship between the same application and resource node 2. It is understandable that each application corresponds to multiple resource nodes 2, and each resource node 2 has an association relationship with one or more resource nodes 2. Based on each application, the topology platform 4 aggregates the network connection information of the multiple resource nodes 2 corresponding to each application to obtain a management relationship between each application and resource node 2. The specific aggregation method is described in detail below.

[0037] Step S108: Import the association relationships into a graph library to generate a dynamic network topology between each application and the resource node 2. It is understood that the topology platform 4 imports the received association relationships between the applications and the resource nodes 2 into a graph library to generate a dynamic topology and display it. The graph library is a topology generation tool.

[0038] In the above embodiment, the access relationship between the application and the resource node 2 is generated into a dynamic topology for display, thereby making it more convenient to uniformly monitor and manage the relationship between the application and the resource node 2.

[0039] Please refer to Figure 2 , which is a first sub-flowchart of the method for processing the dynamic topology of network connections provided by an embodiment of the present application. Step S106 specifically includes the following steps S202-S206.

[0040] In step S202, a matching relationship between the application and the resource nodes is obtained based on the matching relationship of the relevant resource nodes obtained by the application. It is understood that a relationship between an access source and an access target exists between resource nodes 2 and resource nodes 2. For multiple resource nodes 2 corresponding to the application, the topology platform 4 determines and obtains a matching relationship between resource nodes 2 and resource nodes 2 among the multiple resource nodes 2 based on the application. In other words, the relationship between the access source and the access target exists between resource nodes 2 and resource nodes 2.

[0041] In step S204, based on the matching relationship between the application and the resource nodes of the same application, the access counts of the resource models in the CMDB corresponding to the corresponding resource nodes are aggregated to obtain the association relationship and the total access count between the resource models in the CMDB corresponding to the application and the resource nodes. It is understandable that one application corresponds to multiple resource nodes 2, one resource node 2 corresponds to one resource model in the CMDB, and a large amount of access information will appear between each resource node 2 and each resource node 2 within a certain period of time. The topology platform 4 aggregates the access information between each resource node 2 and each resource node 2 to obtain the total number of accesses and the corresponding access time between each resource node 2 and each resource node 2 within a certain period of time.

[0042] Step S206: After aggregation, the last access time between the application and the resource model in the CMDB corresponding to the resource node is recorded. It is understood that, given multiple access times in the access information between each resource node 2, the topology platform 4, based on the rules, only retains the last access time between each resource node 2 and each resource node 2, and records the last access time between each resource node 2.

[0043] Please refer to Figure 3 , which is a second sub-flowchart of the method for processing the dynamic topology of network connections provided by an embodiment of the present application. Step S104 specifically includes the following steps S302-S308.

[0044] Step S302: parse the received network connection information of the resource nodes 2 to obtain information about the resource nodes 2 in the connection information. It is understood that after the topology platform 4 obtains the network connection information of the resource nodes 2, it parses the obtained data to obtain the IP address and port number of each resource node 2 as the access source in each network connection, the IP address and port number of the target accessed by each resource node 2, the access time of each resource node 2, and the number of accesses to each resource.

[0045] Step S304: Determine whether all of the parsed resource nodes 2 correspond to the preset resource models in the CMDB. It is understandable that the topology platform 4 determines the parsed resource nodes 2 based on the preset resource models in the CMDB 3 to determine whether all of the parsed resource nodes 2 correspond to the preset resource models in the CMDB 3. Each resource node 2 corresponds to each preset resource model in a one-to-one manner. When a resource node 2 has a corresponding preset resource model in the CMDB 3, the topology platform 4 determines that the current resource node 2 has a corresponding preset resource model. When a resource node 2 does not have a corresponding preset resource model in the CMDB 3, the CMDB 3 determines that the current resource node 2 does not have a corresponding preset resource model.

[0046] In step S306, when it is determined that all of the resource nodes 2 exist in the preset resource model in the CMDB 3, the resource nodes 2 are matched to obtain a first matching relationship. It is understood that when the obtained resource nodes 2 have corresponding resource models, the topology platform 4 connects the associations between the resource nodes 2 according to the preset resource model to obtain the first matching relationship.

[0047] In step S308, when it is determined that there are resource nodes 2 among the plurality of resource nodes 2 that are not included in the preset resource model of the CMDB 3, the resource nodes 2 that are not included in the preset resource model of the CMDB 3 are stored in the to-be-processed nodes in the CMDB 3 so that the resource nodes 2 in the preset resource model of the CMDB 3 are connected and matched with the to-be-processed nodes in the CMDB 3 to obtain a second matching relationship. It is understandable that when there are resource nodes 2 among the acquired plurality of resource nodes 2 that do not correspond to the preset resource model in the CMDB 3, the topology platform 4 stores the resource nodes 2 that do not correspond to the preset resource model in the unprocessed nodes in the CMDB 3, and the resource nodes 2 among the plurality of resource nodes 2 stored in the unprocessed nodes continue to maintain their association with the associated resource nodes 2.

[0048] Please refer to Figure 4 , which is the third sub-flowchart of the method for processing the dynamic topology of network connections provided by the embodiment of the present application. After step S108, the following steps S402-S408 are specifically included.

[0049] Step S402: Associating the applications in the generated dynamic topology with the corresponding applications in the alarm platform. It is understood that accessing the alarm platform on the topology platform 4 is used to associate the applications on the topology platform 4 with the applications on the alarm platform, so that the applications on the topology platform 4 can obtain the relevant alarm information of the applications on the alarm platform.

[0050] In step S404, when an alarm occurs for an application on the alarm platform, the alarm platform synchronizes the application's alarm information with the network dynamic topology corresponding to the application. It is understood that when an application on the alarm platform generates an alarm, the alarm platform sends the alarm information and application information of the application generating the alarm to the topology platform 4. The topology platform 4 synchronizes the obtained alarm information of the application generating the alarm with the network dynamic topology corresponding to the application.

[0051] Step S406, the alarm information of the application obtained is displayed on the corresponding application in the dynamic topology where the application exists. It can be understood that when the topology platform 4 receives the alarm information and the corresponding alarm application sent by the alarm platform, the topology platform 4 searches for the corresponding application in the topology, and displays the alarm logo on the application, and displays the alarm information and the button to jump to the alarm platform in the logo. That is to say, when the user clicks the alarm logo, a window will appear, displaying the alarm information of the application in the window, and displaying a button to jump to the alarm platform to view more alarm information. When the user clicks the jump button, he can directly jump to the alarm interface of the application to view more alarm information about the application.

[0052] Step S408: In response to the user's viewing operation, the dynamic network topology is used to determine whether there are any alarms in the upstream and downstream of the application. It is understood that the user can select an application to generate a dynamic topology. The topology platform 4 will automatically generate information about the upstream and downstream applications of the corresponding application and the network connection status of the upstream and downstream applications and the current application based on the user-selected application. The user can clearly see on the topology platform 4 whether there are any alarms in the upstream and downstream of the selected application, thereby determining whether there are any alarms in the upstream and downstream of the current application, which is helpful for troubleshooting.

[0053] In the above embodiment, by associating the alarm platform, it is possible to check whether there are alarms in the upstream and downstream of the application according to the access relationship, so that the alarm source can be quickly located.

[0054] Please refer to Figure 5 , which is the fourth sub-flowchart of the method for processing the dynamic topology of network connections provided by the embodiment of the present application. After step S108, the following steps S502-S506 are specifically included.

[0055] Step S502, detects whether the application in the dynamic topology has an active-active scenario, and the active-active scenario is an active-active backup method between the primary and backup data centers of the application. It can be understood that when an application is working in the primary data center, but now the application needs to work in both the primary and backup data centers, an active-active scenario will occur in the application. The topology platform 4 needs to detect whether the application has an active-active scenario based on the network connection status of the application. When the topology platform 4 detects that the network connection status of the application is only in the primary data center or the backup data center, the topology platform 4 determines that the application does not have an active-active scenario; if the network connection status of the application has access not only to the primary data center but also to the backup data center, the topology platform 4 determines that the application has an active-active scenario. In other embodiments, it can also be used for situations where an application exists in multiple data centers.

[0056] In step S504, when it is detected that the application is in an active-active scenario, the firewall policies for related applications are sorted out based on the application's call relationships. It is understandable that because both the primary and standby data centers have their own dedicated firewalls, and each firewall has a different domain name, when the application's network connection information contains different domain names, the topology platform 4 determines that an active-active scenario exists. Based on the application's access information in the data center with activated firewall policies, the topology platform 4 sorts out the firewall policies for the application in the data center without activated firewalls.

[0057] Step S506: Display the firewall policies of the related applications. It is understandable that the topology platform 4 displays the firewall policies of the applications in the data center without firewalls sorted out in step S504 on the corresponding applications on the topology platform 4 through firewall identifiers.

[0058] In the above embodiment, by determining whether the application has an active-active scenario and sorting out the calling relationship of the application, the firewall policy is displayed, so that developers can open the firewall in advance to avoid application access failures.

[0059] Please refer to Figure 6 , which is the fifth sub-flowchart of the method for processing the dynamic topology of network connections provided by the embodiment of the present application. After step S108, the following steps S602-S604 are specifically included.

[0060] Step S602: Displaying the user's operating permissions for each application in the dynamic topology. It is understood that the administrator performs unified management and configuration of users on the topology platform 4. After the administrator completes the configuration, each application will display the users who can operate on each resource node 2 corresponding to the application and the corresponding operating permissions.

[0061] Step S604: respond to user operations and perform addition, modification and deletion of each application operation permission. It is understandable that the administrator can directly add, modify and delete the operation permission of the clicked application on the topology platform 4, and non-administrators cannot do so.

[0062] In the above embodiment, the administrator sorts out the resource nodes 2 that can be operated by the user on the topology platform 4 and configures each resource accordingly to achieve the principle of minimum authorization, thereby preventing the user management authority from being confused or excessive, resulting in misoperation and causing faults.

[0063] Please refer to Figure 7 , which is the sixth sub-flowchart of the method for processing the dynamic topology of network connections provided by the embodiment of the present application. After step S108, the following steps S702-S706 are specifically included.

[0064] In step S702, when an application in the dynamic topology is taken offline, it is determined whether there is an access relationship with the application. It is understood that when a resource node 2 or application needs to be taken offline due to a change in the application architecture, or a problem with the application requires the application to be taken offline, the topology platform 4 will detect whether there is an access relationship with the resource node 2 or application to be taken offline according to a preset time interval.

[0065] In step S704, when the application has an access relationship, a prompt is displayed indicating that the access relationship exists and that the user is not allowed to log off. It is understood that when the topology platform 4 detects that the offline resource node 2 or application has an access relationship within a preset time interval, when the user logs off the resource node 2 or application, the topology platform 4 will display a window prompt indicating that the offline resource node 2 or application has an access relationship, and prompting that the logoff has failed or is not allowed.

[0066] Step S706: When the application does not have an access relationship, a prompt indicating that the offline is successful is displayed. It is understandable that when the topology platform 4 detects that the offline resource node 2 or application does not have an access relationship within a preset time interval, when the user logs off the resource node 2 or application, the topology platform 4 will directly log off the resource node 2 or application that the user wants to log off and prompt that the offline is successful.

[0067] Please refer to Figure 8, which is a schematic diagram of the internal structure of a computer device provided in an embodiment of the present application. The computer device 10 includes a computer-readable storage medium 11, a processor 12, and a bus 13. Among them, the computer-readable storage medium 11 includes at least one type of readable storage medium, which includes a flash memory, a hard disk, a multimedia card, a card-type memory (for example, SD or DX memory, etc.), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the computer-readable storage medium 11 can be an internal storage unit of the computer device 10, such as a hard disk of the computer device 10. In other embodiments, the computer-readable storage medium 11 can also be an external storage device of the computer device 10, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. equipped on the computer device 10. Furthermore, the computer-readable storage medium 11 can also include both an internal storage unit of the computer device 10 and an external storage device. The computer-readable storage medium 11 can be used not only to store application software and various types of data installed on the computer device 10, but also to temporarily store data that has been output or is to be output.

[0068] The bus 13 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0069] Furthermore, the computer device 10 may also include a display component 14. The display component 14 may be a light emitting diode (LED) display, a liquid crystal display (LCD), a touch-sensitive liquid crystal display (LCD), or an organic light emitting diode (OLED) touchscreen. The display component 14 may also be appropriately referred to as a display device or a display unit, and is used to display information processed by the computer device 10 and to display a visual user interface.

[0070] Furthermore, the computer device 10 may further include a communication component 15. The communication component 15 may optionally include a wired communication component and / or a wireless communication component, such as a WI-FI communication component, a Bluetooth communication component, etc., and is generally used to establish a communication connection between the computer device 10 and other intelligent control devices.

[0071] In some embodiments, the processor 12 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip, configured to execute program code or process data stored in the computer-readable storage medium 11. Specifically, the processor 12 executes a processing program to control the computer device 10 to implement a dynamic topology processing method for network connections.

[0072] Understandably, Figure 8 Only the computer device 10 having components 11-15 and a dynamic topology processing method of network connections is shown. It can be understood by those skilled in the art that Figure 8 The illustrated structure does not constitute a limitation on the computer device 10 , and the computer device 10 may include fewer or more components than shown, or may combine certain components, or arrange the components differently.

[0073] Obviously, those skilled in the art may make various modifications and variations to this application without departing from the spirit and scope of this application. Thus, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application is intended to include such modifications and variations.

[0074] The above examples are merely preferred embodiments of the present application and are not intended to limit the scope of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope of the present application.

Claims

1. A method for processing dynamic topology of a network connection, characterized in that: The method for processing the dynamic topology of a network connection includes: Obtaining network connection status of several resource nodes, wherein the network connection status is the access time and access count between an access source and an access target, and the access source and the access target are the resource nodes that issue access requests and the resource nodes that respond to the access requests, respectively; The network connection status of several received resource nodes is matched according to the preset resource model in the CMDB to obtain a matching relationship; Aggregate the matching relationships related to the same application to obtain the association relationship between the same application and resource nodes; The association relationship is imported into a graph library to generate a network dynamic topology between each application and the resource node, and the network dynamic topology is used to monitor and manage the relationship between each application and the resource node.

2. The method for processing dynamic topology of a network connection according to claim 1, wherein: The association relationships between the same application and resource nodes are obtained by aggregating the matching relationships related to the same application, including: Obtaining a matching relationship between the application and the resource nodes based on the matching relationship of the related resource nodes; Aggregating the number of accesses to the resource models in the CMDB corresponding to the corresponding resource nodes based on the matching relationship between the applications and resource nodes of the same application to obtain the association relationship and the total number of accesses to the resource models in the CMDB corresponding to the applications and resource nodes; After aggregation, the last access time between the application and the resource model in the CMDB corresponding to the resource node is recorded.

3. The method for processing dynamic topology of a network connection according to claim 1, wherein: Matching the network connection conditions of the received resource nodes according to the preset resource model to obtain a matching relationship specifically includes: Analyzing the network connection status of the received resources to obtain information of the resource nodes in the connection status; Determining whether all of the resource nodes in the parsed resource node information exist in a preset resource model of the CMDB; When it is determined that all of the resource nodes exist in the preset resource model of the CMDB, matching the resource nodes to obtain a first matching relationship; When it is determined that there are resource nodes in the plurality of resource nodes that are not in the preset resource model of the CMDB, the resource nodes that are not in the preset resource model of the CMDB are stored in the nodes to be processed in the CMDB so that the resource nodes in the preset resource model of the CMDB are connected and matched with the nodes to be processed in the CMDB to obtain a second matching relationship.

4. The method for processing dynamic topology of a network connection according to claim 1, wherein: Putting the association relationship into the graph library to generate the dynamic network topology between each application and the resource node specifically includes: Associating the applications in the generated dynamic topology with the corresponding applications in the alarm platform; When an alarm occurs in the application in the alarm platform, the alarm platform synchronizes the alarm information of the application to the network dynamic topology corresponding to the application; The obtained alarm information of the application is displayed on the corresponding application in the dynamic topology where the application exists.

5. The method for processing dynamic topology of network connections according to claim 4, wherein: The method further comprises: In response to the user's viewing operation, whether there are any alarms in the upstream and downstream of the application is obtained according to the network dynamic topology.

6. The method for processing dynamic topology of a network connection according to claim 1, wherein: After the association relationship is placed in the graph library to generate the dynamic network topology between each application and the resource node, the following steps are specifically included: Detect whether an application in a dynamic topology has an active-active scenario, where the active-active scenario is an active-active backup mode between the primary and standby data centers of the application; When it is detected that the application has an active-active scenario, the firewall policy of the related application is sorted out according to the calling relationship of the application; The firewall policy applied to the sorted correlation is displayed.

7. The method for processing dynamic topology of a network connection according to claim 1, wherein: After the association relationship is placed in the graph library to generate the dynamic network topology between each application and the resource node, the following steps are specifically included: Display the user's operation permissions for each application in the dynamic topology; In response to user operations, the permissions for each application are added, modified, and deleted.

8. The method for processing dynamic topology of network connections according to claim 1, wherein: After the association relationship is placed in the graph library to generate the dynamic network topology between each application and the resource node, the following steps are specifically included: When an application in a dynamic topology is offlined, determining whether the application has an access relationship; If the application has an access relationship, it will prompt that there is an access relationship and it is not allowed to go offline; When there is no access relationship between the application and the user, a prompt will be displayed indicating that the user has successfully logged off.

9. A computer device, characterized in that: The computer equipment specifically includes: a computer-readable storage medium for storing program instructions; and The program instructions are executed by the processor to implement the dynamic topology processing method for network connection according to any one of claims 1 to 8.

10. A dynamic topology processing system for network connections, characterized in that: The dynamic topology processing system for network connections specifically includes: A plurality of resource nodes, each resource node including a collection component for collecting network connection status of each resource node, wherein the network connection status is access time and access count between an access source and an access target, wherein the access source and the access target are resource nodes that issue access requests and resource nodes that respond to the access requests, respectively; CMDB, used to store preset resource models; The topology platform includes an acquisition module, a matching module, an aggregation module and a generation module. The acquisition module is used to receive the network connection status of several resource nodes reported by the acquisition component. The matching module is used to match the received network connection status of the several resource nodes according to the preset resource model in the CMDB to obtain a matching relationship. The aggregation module is used to aggregate the matching relationships related to the same application to obtain the association relationship between the same application and the resource node; the generation module is used to put the association relationship into the library to generate a network dynamic topology between each application and the resource node. The network dynamic topology is used to monitor and manage the relationship between each application and the resource node.

Citation Information

Patent Citations

  • Method and device for constructing network call relationship topological graph

    CN110784358A