Diagnosing an intermediate network node
By exchanging diagnostic transmissions between network nodes, unknown network nodes can be identified and isolated, solving the problem of network controllers being unable to identify them and ensuring network security and functional stability.
Patent Information
- Application Number
- CN202180047393.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-06-09
- Filing Date
- 2021-06-08
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2041-06-08
AI Technical Summary
The network controller's inability to identify unknown network nodes can lead to network function interruptions or security risks, especially since malicious nodes may hide and attack the network.
By exchanging diagnostic transmissions between network nodes, the presence and functional abnormalities of intermediate nodes are identified using methods such as address, data type, cable length, and tags, and the network topology is updated to prevent data traffic from passing through unknown nodes.
Effectively identify and isolate unknown network nodes to prevent network outages and security threats, and ensure the normal operation of network functions.
Smart Images

Figure CN115885502B_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This patent application claims priority to U.S. Patent Application No. 16 / 897,128, filed June 9, 2020, which is incorporated herein by reference in its entirety. Technical Field
[0003] This disclosure generally relates to diagnosing network nodes in a networked environment. Using the various techniques described herein, the presence and functionality of network nodes in a networked environment can be identified. Background Technology
[0004] Modern computing networks can include multiple devices, services, and other network nodes interconnected through various interfaces. The network can be managed by a central network controller that tracks the network topology. That is, the network controller tracks the devices within the network and the connections between them. To keep the topology up-to-date when adding or removing network nodes, the network controller can rely on announcements from the network nodes. These announcements may include, for example, Link Layer Discovery Protocol (LLDP) messages. In some cases, administrators can manually update the topology.
[0005] However, in some situations, the network controller may not be aware of nodes that have joined the network. For example, a node might connect to the network without sending an announcement throughout the network. Therefore, the network controller may not be aware of the node. In some cases, the node might be a BitW (Bump-in-the-Wire) device.
[0006] Unknown network nodes can cause a variety of problems. In some cases, unknown network nodes may be benign. For example, an administrator might add a transparent firewall node to the network without updating the topology. Furthermore, a transparent firewall node may not advertise its existence within the network. Therefore, the network controller associated with the network may be unaware of the new firewall node. In other cases, unknown network nodes can disrupt network functionality. For example, a firewall node might unintentionally delay and / or drop data packets transmitted throughout the network, potentially disrupting network communication.
[0007] Furthermore, malicious actors may connect deliberately hidden malicious nodes to the network. For example, snooping nodes configured to capture and analyze private network traffic may be added to the network. In some cases, snooping nodes can report private network traffic to unauthorized external parties, creating security vulnerabilities within the network. In other cases, malicious network nodes may exploit vulnerabilities within the network or even leak data outside the network. Therefore, hidden nodes pose a significant security risk to the network. Thus, it is necessary to identify unknown network nodes within the network. Attached Figure Description
[0008] Detailed description is given below with reference to the accompanying drawings. In the drawings, the leftmost digit of the reference number indicates the drawing in which the reference number first appears. The same reference number is used in different drawings to denote similar or identical items. The systems depicted in the drawings are not scaled, and the components in the drawings may be depicted to different scales.
[0009] Figure 1 An example environment for diagnosing intermediate nodes within a network is shown.
[0010] Figure 2A and Figure 2B It shows in Figure 1 An example of signals transmitted between various components within the shown environment. Figure 2A Example signaling from a sending node is shown for diagnosing intermediate nodes within a network. Figure 2B An alternative example signaling for a receiving node used to diagnose intermediate nodes within a network is shown.
[0011] Figures 3A to 3G Various examples of diagnostic transports that can be used to diagnose intermediate nodes within a network are shown. Figure 3A Example signaling using address-based diagnostic tests is shown. Figure 3B Example signaling using diagnostic tests based on corrupted data is shown. Figure 3C Example signaling using diagnostic tests based on malicious data is shown. Figure 3D Example signaling using time-based diagnostic tests is shown. Figure 3E Example signaling using a diagnostic test based on cable length is shown. Figure 3F Example signaling for diagnostic tests using tag-based traffic is shown. Figure 3G Example signaling using diagnostic tests based on large-scale traffic is shown.
[0012] Figure 4 An example procedure is shown for diagnosing the presence and / or functional abnormalities of intermediate nodes within a network.
[0013] Figure 5 An example procedure for identifying the presence of intermediate nodes within a network is shown.
[0014] Figure 6 An example computer architecture is shown that enables a computer to execute program components for implementing the functions described herein. Detailed Implementation
[0015] Overview
[0016] All aspects of the invention are set forth in the independent claims, and preferred features are set forth in the dependent claims. A feature of one aspect may be applied alone to any aspect or in combination with other aspects to any aspect.
[0017] This disclosure describes various systems, devices, and methods for diagnosing nodes within a network. In an example method, a first network node receives an indication of a diagnostic transmission originating from a second network node. The first network node also receives a forwarded transmission corresponding to the diagnostic transmission. Based on at least one of the indication from the forwarded transmission and the indication from the diagnostic transmission, the presence and / or functional abnormalities of an intermediate node between the first and second network nodes can be diagnosed.
[0018] In some cases, the method includes sending a report to the network controller indicating the presence and / or malfunction of an intermediate node between the first and second network nodes.
[0019] According to some examples, the header of a diagnostic transport includes a first address, and the payload of the diagnostic transport also includes the first address; the header of a forwarding transport includes a second address, and the payload of the forwarding transport includes the first address. The presence and / or functional abnormalities of intermediate nodes can be diagnosed by determining that the first address in the payload of the forwarding transport differs from the second address in the header of the forwarding transport.
[0020] In some examples, the diagnostic transmission includes both corrupted and uncorrupted data, and the forwarding transmission includes uncorrupted data but omits the corrupted data. For example, diagnosing the presence and / or functional abnormality of an intermediate node includes determining that the forwarding transmission omitted corrupted data. In some cases, the corrupted data is first corrupted data associated with a first layer, the diagnostic transmission also includes second corrupted data associated with a second layer, which is different from the first layer, and the forwarding transmission also includes the second corrupted data. In some examples, the method further includes: determining that the intermediate node is active in the first layer based on the absence of the first corrupted data in the forwarding transmission; and determining that the intermediate node is invisible in the second layer based on the presence of the second corrupted data in the forwarding transmission.
[0021] In some cases, diagnostic transmissions include a first packet and a second packet. The first packet may include inert malicious data, and the second packet may include non-malicious data. Forwarding transmissions may include the second packet and omit the first packet. In some examples, diagnosing the presence and / or malfunction of intermediate nodes includes determining that a forwarding transmission missed the first packet.
[0022] According to some examples, diagnostic transmissions include a first type of data and a second type of data. Forwarding transmissions may include both first and second types of data. In some cases, diagnosing the presence and / or functional abnormalities of intermediate nodes includes determining that the first time the first type of data in a forwarding transmission is received differs from the second time the second type of data in a forwarding transmission is received.
[0023] In some examples, diagnostic transmissions include at least one first packet and an in-band Operation, Maintenance, and Management (iOAM) tag indicating the first content of the at least one first packet. Forwarding transmissions may include at least one second packet and an iOAM tag. In some cases, the presence of an intermediate node is identified at least in part based on the iOAM tag in the forwarding transmission indicating first content that differs from the second content of the at least one second packet.
[0024] Example Implementation
[0025] This disclosure describes various techniques for diagnosing network nodes within a network. According to some examples, one or more unknown network nodes may be connected between two diagnostic network nodes. The two diagnostic network nodes can perform one or more diagnostic tests by exchanging transmissions across the unknown network node(s). Based on the results of the tests, one or both of the diagnostic network nodes can identify the presence of the unknown network node(s). Furthermore, some tests can be used to identify one or more layers visible above the unknown network node(s), thereby identifying the type of the unknown network node(s). In various cases, one or both of the diagnostic network nodes can notify other network nodes within the network (e.g., switches, routers, load balancers, network controllers, etc.) of the presence and / or type of the unknown network node(s). Thus, various nodes within the network can suppress the routing of data traffic through the unknown network node(s) and utilize different paths for routing through the network. In various examples, tests can be performed on one or more known network nodes to determine if the known network node(s) is malfunctioning. If the known network node(s) is malfunctioning, the diagnostic network node can indicate the malfunctioning known network node(s) to other network nodes or a central control system.
[0026] The various implementations described herein aim to practically improve network environments. The example techniques described in this disclosure enable the identification of unknown network nodes (whether benign or malicious) within a network. Furthermore, some techniques can be used to identify whether known network nodes are malfunctioning. These techniques for diagnosing the presence and / or functionality of network nodes can be used to prevent network outages and security risks.
[0027] Furthermore, the various examples described herein cannot be practically executed in the human brain. According to some examples, diagnosing intermediate network nodes involves monitoring data in diagnostic and / or forwarding transmissions through the network environment. The human brain lacks the capacity to perform these techniques. This disclosure provides non-abstract techniques that are essentially integrated into the network environment.
[0028] Various embodiments of this disclosure will be described in detail with reference to the accompanying drawings, wherein the same reference numerals in the various figures denote the same parts and components. Furthermore, any samples listed in this specification are not intended to be limiting, but merely illustrate some of the many possible implementations.
[0029] Figure 1 An example environment 100 for diagnosing intermediate nodes within a network is illustrated. As shown, environment 100 includes an internal network 102 comprising multiple network nodes. As used herein, the terms "node," "network node," and their equivalents may refer to any entity within the network capable of sending packets to and / or receiving packets from at least one other node. A node may be a device, software instance, virtual machine (VM), container, virtual process, etc. In some examples, a node may include a set of devices or virtual resources, such as a security group, subnet, etc. In some examples, a node may be a client, server, or a combination thereof. Specifically, internal network 102 may include a first network node 104 and a second network node 106. In some implementations, network nodes within internal network 102 may be interconnected via interfaces according to Clos topology, ridge topology, etc.
[0030] Furthermore, the internal network 102 may include a controller 108. As used herein, the terms "network controller," "controller," and their equivalents may refer to the entity that provides centralized automation, management, policy programming, application deployment, and / or health monitoring for the structure of the internal network 102. In some cases, controller 108 may be embodied in the Application Policy Infrastructure Controller (APIC). TM The controller 108 may be embodied in one or more network nodes within the internal network 102. In some cases, the controller 108 may analyze data traffic through the internal network 102, receive reports that enable the controller 108 to identify the functions performed by various network nodes within the internal network 102, monitor the capacity utilized within the network 102, etc. In some cases, the controller 108 is configured to direct various functions of the first network node 104 and / or the second network node 106, as well as any other network node within the internal network 102. Therefore, the controller 108 can optimize the utilization of network resources (e.g., communication resources, processing resources, memory resources, etc.) within the internal network 102 by controlling the network nodes.
[0031] In some cases, internal network 102 may include load balancer 110. As used herein, the term "load balancer" and its equivalents may refer to an entity configured to distribute workloads across a limited number of resources to ensure workload distribution across resources. In some examples, a load balancer may distribute data traffic across different paths within internal network 102 to prevent overloading of one or more communication resources. In some cases, a load balancer may distribute the execution of tasks across different network nodes within internal network 102 to prevent overloading of one or more network nodes. In some cases, a load balancer may be implemented by a network node (e.g., a device, VM, or application executed by at least one device, network infrastructure controller, etc.). For example, a load balancer may distribute network traffic evenly across multiple switches within an example network. Figure 1 The load balancer 110 can be implemented in one or more network nodes within the internal network 102.
[0032] Internal network 102 may include one or more internal communication networks 112 through which data can be transmitted between nodes within internal network 102. As used herein, the term "communication network" and its equivalents may refer to a network comprising one or more nodes and / or one or more interfaces (through which data can be transmitted). As used herein, the term "interface" and its equivalents may refer to a connection between two nodes in a network (e.g., nodes within internal network 102). In some cases, an interface may directly connect two nodes and / or omit any intermediate nodes. An interface may connect to a first port of a first network node (e.g., a physical port of a device and / or a virtual port of a software instance) and a second port of a second network node. In some cases, the interface between two nodes may be a wired interface, allowing packets to be transmitted as signals conducted through a solid medium (e.g., Ethernet cable, fiber optic cable, etc.) connecting the two nodes. In some examples, the interface between nodes may be a wireless interface, allowing packets to be transmitted as signals through a fluid medium (e.g., air, water, etc.) connecting the two nodes. A wireless interface can be defined based on the type of wave used to carry the signal (e.g., sound wave, electromagnetic wave, etc.) and the frequency of the wave (e.g., ultrasonic, radio frequency, infrared frequency, etc.). The interface can also be defined based on a specific communication protocol, which instructs how the data transmitted through the interface should be modulated. Some examples of communication protocols suitable for this application include Transmission Control Protocol (TCP) / Internet Protocol (IP), Wi-Fi, Bluetooth, etc. In various examples, communication network(s) 112 may include at least one wired (e.g., fiber optic) network through which nodes within internal network 102 can transmit data.
[0033] Depending on the implementation, internal network 102 may be further connected to one or more external networks 114. The external networks 114 may be connected to one or more communication networks 112 of internal network 102. Some examples of external networks 114 include public networks, wide area networks (WANs), or combinations thereof. For example, external networks 114 may include the Internet, radio access networks (RANs), wireless core networks (e.g., evolved packet core (EPC) networks, fifth-generation core (5GC) networks, etc.).
[0034] One or more user equipments 116 can connect to the internal network 102 via one or more external networks 114. For example, one or more user equipments 116 can send data to or receive data from at least one node in the internal network 102 via one or more external networks 114. As used herein, the terms “user equipment,” “wireless communication device,” “communication device,” “mobile device,” “client device,” and “terminal” are used interchangeably to describe any user equipment (UE) capable of sending / receiving data (e.g., wirelessly) using any suitable communication / data technology, protocol, or standard, such as Global System for Mobile Communications (GSM), Time Division Multiple Access (TDMA), Universal Mobile Telecommunications System (UMTS), Evolved Data Optimized (EVDO), Long Term Evolution (LTE), LTE-Advanced (LTE+), New Radio (NR), Generic Access Network (GAN), and Unlicensed Mobile Access Network (UCAN). Access (UMA), Code Division Multiple Access (CDMA), Orthogonal Frequency Division Multiple Access (OFDM), General Packet Radio Service (GPRS), Enhanced Data GSM Environment (EDGE), Advanced Mobile Phone System (AMPS), High-Speed Packet Access (HSPA), Evolved HSPA (HSPA+), Voice over Internet Protocol (IP) (VoIP), Voice over LTE (VoLTE), Institute of Electrical and Electronics Engineers (IEEE) 802.1x protocol, WiMAX, Wi-Fi, Cable Data Service Interface Specification (DOCSIS), Digital Subscriber Line (DSL), and / or any future IP-based network technology or evolution of existing IP-based network technologies. Typically, a UE can be implemented as any suitable type of computing device configured to communicate via wired or wireless networks, including but not limited to mobile phones (e.g., smartphones), tablet computers, laptop computers, portable digital assistants (PDAs), wearable computers (e.g., electronic / smart glasses, smartwatches, fitness trackers, etc.), Internet of Things (IoT) devices, in-vehicle (e.g., car) computers, and / or any similar mobile devices, as well as location-based computing devices, including but not limited to televisions (smart TVs), set-top boxes (STBs), desktop computers, etc.
[0035] In some cases, internal network 102 may include firewalls and / or other security policies configured to filter and / or isolate potentially malicious traffic from one or more external networks 114 and one or more user devices 116. The firewalls and / or security policies may be embodied within one or more nodes of internal network 102. In various examples, an example firewall may intercept data traffic sent to or passing through internal network 102 (e.g., data traffic sent between one or more communication networks 112 and one or more external networks 114), examine the data traffic based on one or more filtering conditions, and selectively block at least a portion of the data traffic that satisfies one or more of the filtering conditions. Therefore, internal network 102 can be protected from malicious data traffic originating outside internal network 102.
[0036] Controller 108 and / or load balancer 110 may maintain (e.g., store) the topology of internal network 102. The topology (also referred to as "network topology") indicates the arrangement of network nodes and interfaces connecting them within internal network 102. In some cases, the topology may further indicate the functionality and / or capacity of the network nodes. In some cases, controller 108 may identify the topology of internal network 102 by receiving one or more announcements (e.g., messages) from network nodes within internal network 102. Controller 108 may utilize the topology to control internal network 102. In some cases, load balancer 110 may utilize the topology to balance the load among various network nodes within internal network 102.
[0037] However, if additional network nodes are added to internal network 102, the topology may become outdated. In some cases, the network administrator can manually update the topology. Depending on some implementations, the topology can be updated based on announcements sent throughout internal network 102 (e.g., LLDP messages). However, in some cases, the topology will not be updated. For example, network nodes may be added to internal network 102 by users who do not manually update the topology. In some cases, network nodes may be benign, but unknown to controller 108, other devices, and / or other users. In some cases, network nodes may be malicious, and users may choose not to update the topology for malicious purposes. In both types of cases, network nodes may cause problems with the functionality of internal network 102.
[0038] In various implementations of this disclosure, the first network node 104 and the second network node 106 can diagnose the presence of an intermediate node 118 within the internal network 102. In some cases, the intermediate node 118 may be a BitW node and / or device, such as a security appliance, a transparent firewall node, etc. The intermediate node 118 may be transparent to the visibility of the internal network 102. In some examples, the controller 108 may maintain the network topology based on communicating with and querying the LLDP database of all network nodes it controls in order to discover network nodes. LLDP is a standardized link-layer protocol defined by IEEE for site and media access control connectivity discovery (specified in IEEE 802.1AB). Example network nodes participating in LLDP can generate and send LLDP messages that announce the node's identity (e.g., the node's address), capabilities, and neighboring nodes. Example network nodes can receive LLDP messages from their neighboring nodes, which the network node can use to identify its neighboring nodes. Example network nodes may further store indications of their neighboring nodes in an LLDP database and report information about their neighboring nodes to controller 108, which can update the topology based on LLDP messages. However, in various examples, intermediate node 118 may be an online intrusion prevention system (IPS) type device that suppresses the generation of LLDP messages that would otherwise identify its presence to its neighbors within the internal network 102. Therefore, intermediate node 118 may be invisible to the internal network 102 and may be undetectable by LLDP-based technologies used to define and update the network topology of the internal network 102. In various implementations, controller 108 may base its updates on messages associated with other discovery protocols sent throughout the internal network 102 (e.g., according to CISCO). TM Discovery Protocol (CDP), Link Layer Topology Discovery (LLTD) protocol, NORTEL TM The network topology is maintained using discovery protocols such as NDP. However, in these implementations, intermediate node 118 may be similarly undetectable when using other discovery protocols. Similarly, intermediate node 118 may be undetectable using tracing routes because intermediate node 118 may suppress and reduce the Time-to-Live (TTL) data field of tracing route packets.
[0039] The first network node 104 may include a first diagnostic system 120. The second network node 106 may include a second diagnostic system 122. The first diagnostic system 120 and / or the second diagnostic system 122 may be included in or embodied in software containers, smart network interface cards (smartNICs), virtualization functions, operating systems (OS), applications, etc. (which may be part of the first network node 104 and / or the first network node 106).
[0040] In various implementations, the first network node 104 and / or the first diagnostic system 120 can participate in the handshake process with the second network node 106 and / or the second diagnostic system 122. For example, the first network node 104 can send an offer message through a specific layer (e.g., layer 2) that announces the capabilities of the first diagnostic system 120. Upon receiving the offer message, the second network node 106 can send an acknowledgment message to the first network node 104 and / or the first diagnostic system 120 through the specific layer, indicating the capabilities of the second diagnostic system 122. Therefore, the first network node 104 and / or the first diagnostic system 120 can synchronize with the second network node 106 and / or the second diagnostic system 122, and can subsequently test the presence of the intermediate node 118.
[0041] Depending on the implementation, the test can be triggered by controller 108. For example, controller 108 can send an activation message to first network node 104 and / or first diagnostic system 120, and second network node 106 and / or second diagnostic system 122. The activation message can be sent via one or more communication networks 112. Upon receiving the activation message, first network node 104, first diagnostic system 120, second network node 106, and / or second diagnostic system 122 can initiate a test to identify the presence of intermediate node 118. In various examples, controller 108 can send the activation message periodically (e.g., every 12 hours, daily, or at some other frequency).
[0042] In some implementations, the first network node 104 and the second network node 106 may be presumed to be adjacent within the internal network 102. As used herein, the term "adjacent" and its equivalents may refer to nodes connected to each other, where communication between nodes does not require routing between other nodes. For example, two adjacent nodes may exchange data through a single network interface. In some cases, nodes may be adjacent within a specific network layer, such that communication between layer-adjacent nodes does not require routing between other nodes within that specific network layer. Nodes within a network are "presumed to be adjacent" when the existing network topology (e.g., stored by the network controller or otherwise maintained) indicates that nodes are adjacent. However, nodes presumed to be adjacent may not actually be adjacent due to the presence of one or more unknown intermediate nodes. Figure 1 In the example shown, the first network node 104 and the second network node 106 can be presumed to be adjacent by the existing topology maintained by the controller 108. However, due to the presence of the intermediate node 118, the first network node 104 and the second network node 106 may not actually be adjacent within the internal network 102.
[0043] To identify the presence of intermediate node 118, first network node 104 and / or first diagnostic system 120 may send a diagnostic transmission to second network node 106 and / or second diagnostic system 122. As used herein, the terms “transmission,” “message,” and their equivalents may refer to data transmitted between network nodes. In some cases, a transmission may include one or more Protocol Data Units (PDUs) (e.g., data packets) transmitted between network nodes. When a transmission is sent by a single network node and received by a single network node, it may be referred to as a “unicast” transmission. When a transmission is sent by a single network node and received by multiple network nodes, it may be referred to as a “multicast” transmission. In various cases, diagnostic transmissions may be sent by first network node 104 and / or first diagnostic system 120 through an interface presumed to connect first network node 106 directly to second network node 106. In some examples, indications for diagnostic transmissions may be further sent by first network node 104 and / or first diagnostic system 120 to second network node 106 and / or second diagnostic system 122 via communication network(s)112.
[0044] If intermediate node 118 is not in the internal network 102, the second network node 106 and / or the second diagnostic system 122 will receive diagnostic transmissions in the expected manner. For example, the received diagnostic transmissions may include the same data as the sent diagnostic transmissions. However, due to the presence of intermediate node 118, diagnostic transmissions may be received in an undesirable manner. That is, the second network node 106 and / or the second diagnostic system 122 may receive forwarded transmissions from intermediate node 118 that may indicate the presence of intermediate node 118. In some cases, the second network node 106 and / or the second diagnostic system 122 may return an indication of a forwarded transmission to the first network node 104 and / or the first diagnostic system 120.
[0045] In some examples, diagnostic transmissions may include the addresses of the first network node 104 and / or the first diagnostic system 120. For example, a diagnostic transmission may include at least one data packet with an address indicating the source of the data packet. As used herein, the term "address" and its equivalents may refer to an identifier of a node within a network that can be used to define the node as a transmission destination. One example of an address type is a Media Access Control (MAC) address as defined by the IEEE 802 standard. A MAC address may include 48 bits that uniquely define a node within a network. Another example of an address type is an IP address, which is defined according to the IP communication protocol developed by the Internet Engineering Task Force (IETF). In IP version 4 (IPv4), an IP address may include 32 bits that uniquely define a node within a network. In IP version 6 (IPv6), an IP address may include 128 bits that uniquely define a node within a network. In some cases, intermediate node 118 may automatically update its address to reflect the address of intermediate node 118. Therefore, forwarding transmissions may include addresses different from those in diagnostic transmissions. Based on this difference, intermediate node 118 can be identified.
[0046] In some cases, diagnostic transmissions may include a mixture of uncorrupted and corrupted data. As used herein, the term "uncorrupted data" and its equivalents may refer to data without errors and / or containing fewer than a threshold amount of errors (e.g., threshold bits). As used herein, the term "corrupted data" and its equivalents may refer to data containing one or more errors. For example, errors may include PDUs sent via non-public ports, acknowledgment messages via connections not yet established, corrupted packet headers, etc. Various network nodes can automatically filter out corrupted data they receive. For example, intermediate node 118 may include uncorrupted data in forwarding transmissions and avoid including corrupted data in forwarding transmissions. Therefore, intermediate node 118 can be identified based on the absence of corrupted data in forwarding transmissions.
[0047] In some examples, diagnostic transports may include a mixture of non-malicious and malicious data. As used herein, the term "malicious data" may refer to data typically associated with malware. Malicious data in diagnostic transports may be benign, thus avoiding exposure of internal network 102 to security risks. For example, the malicious data may include European Institute for Computer Virus Research (EICAR) test files. However, the malicious data may include data with one or more patterns known to be associated with malware, and therefore may be filtered out or isolated by conventional firewalls and / or security platforms. In some cases, intermediate node 118 may apply security policies that filter out malicious data. Therefore, intermediate node 118 may include non-malicious data in forwarded transports and may avoid including malicious data in forwarded transports. Since no malicious data is present in the forwarded transports, intermediate node 118 can be identified.
[0048] In some instances, diagnostic transmissions may include a mixture of different types of data. As used herein, the terms “type,” “data type,” “data type,” and their equivalents may refer to data that is encapsulated, formatted, and / or encoded in a particular manner. Some examples of different types of data include raw Internet Protocol (IP) data, Transmission Control Protocol (TCP) data, User Datagram Protocol (UDP) data, Internet Control Message Protocol (ICMP) data, Hypertext Transfer Protocol (HTTP) data, Secure Sockets Layer (SSL) or Transport Layer Security (TLS) data, etc. In some cases, intermediate node 118 may process different types of data at different rates. For example, intermediate node 118 may perform deep packet inspection on a certain type of data included in a diagnostic transmission, which may slow down the processing of that type of data. Therefore, the second network node 106 and / or the second diagnostic system 122 may receive different types of data in the forwarding transmission at different times. The difference in the timing of receiving different types of data can be used to identify the presence of intermediate node 118.
[0049] In various examples, the first network node 104 can perform a cable length test on its interface toward the second network node 106 to identify the length of a first cable connecting the first network node 106 to the intermediate node 118. Similarly, the second network node 106 can perform a cable length test on its interface toward the first network node 104 to identify the length of a second cable connecting the second network node 106 to the intermediate node 118. In some cases, diagnostic transmissions may include a data field indicating the length of the first cable. The intermediate node 118 may forward this data field in a forwarding transmission. The second network node 106 may compare the length of the first cable indicated in this data field with the length of the second cable. The first and second cables may have different lengths. Different cable lengths can be used to identify the presence of the intermediate node 118.
[0050] Depending on some implementations, a diagnostic transport may include some existing data traffic sent from a first network node 104 to a second network node 106. The diagnostic transport may further include one or more tags indicating the data in the diagnostic transport. For example, the tags(s) may include an in-band OAM (iOAM) classifier indicating each packet in the diagnostic transport. The iOAM classifier is defined according to the Internet Engineering Task Force (IETF) and may provide real-time telemetry data that can be embedded in the real-time data traffic. Examples of iOAM classifiers that may be included in one or more tags include node identifiers (IDs) of nodes from which diagnostic transmissions are sent and / or through which diagnostic transmissions pass (e.g., first network node 104, second network node 106, and / or intermediate node 118), ingress and / or egress interfaces (e.g., interfaces between first network node 104, second network node 106, and / or intermediate node 118), timestamps (e.g., timestamps for first network node 104, second network node 106, and / or intermediate node 108 generating and / or sending diagnostic transmissions), relay delays, relay jitter, sequence numbers, application-defined metadata, hashes of transmitted packets, etc. In some cases, one or more tags may directly indicate the presence of intermediate node 118. For example, second network node 106 may identify the presence of intermediate node 118 in one or more tags in response to recognizing that the node ID of intermediate node 118 is present in the tags. In some cases, one or more tags can indicate the content of a packet sent from the first network node 104 (e.g., a hash of the content, the node that sent the packet, etc.), which may differ from the content of a received packet (this can indicate the presence of an intermediate node 118). For example, if one or more tags indicate that the first network node 104 is the sender of the packet, but the content of the packet (e.g., the header and / or payload) indicates different content, the presence of an intermediate node 118 can be identified. Alternatively, the presence of an intermediate node 118 can be identified indirectly based on one or more tags. For example, an intermediate node 118 may drop at least some packets, causing the forwarding transmission to miss at least some packets and one or more tags included in the diagnostic transmission. One or more tags in the forwarding transmission can be used to identify that at least some packets were dropped. Therefore, the presence of an intermediate node 118 can be identified due to the dropped packets.
[0051] In various examples, diagnostic transmissions may include one or more metrics indicating data traffic previously sent by first network node 104 and addressed to second network node 106. For example, a diagnostic transmission may indicate the number of packets sent by first network node 104 within a specific time interval. Similarly, forwarding transmissions may indicate the number of packets. Upon receiving a forwarding transmission, second network node 106 can compare the number of data packets sent by first network node 104 with the number of data packets received by second network node 106. If a difference exists between the number of sent and received packets, the presence of intermediate node 118 can be identified.
[0052] In some cases, the first network node 104 and / or the first diagnostic system 120 may send multiple diagnostic transmissions to the second network node 106 and / or the second diagnostic system 122 to identify the presence of the intermediate node 118. For example, diagnostic transmissions may be sent through different layers. As used herein, the terms "layer," "abstraction layer," and their equivalents may refer to one or more network nodes exchanging data via standardized communication protocols. The Open Systems Interconnection (OSI) model (defined by the International Organization for Standardization (ISO)) is an example of such a conceptual model characterized by multiple layers, each with its own communication protocol. For example, Layer 1 in the OSI model is defined as the "Physical" layer, which governs the transmission of bit streams over the physical medium; Layer 2 is defined as the "Data Link" layer, which governs data transmission between nodes connected through the physical layer; Layer 3 is defined as the "Network" layer, which governs routing, addressing, and flow control on multi-node networks; Layer 4 is defined as the "Transport" layer, which governs the transmission of data segments throughout the network; Layer 5 is defined as the "Session" layer, which governs continuous sessions between nodes; Layer 6 is defined as the "Representation" layer, which governs the translation of data between network services and applications; and Layer 7 is defined as the "Application" layer, which governs data transmitted through application programming interfaces (APIs), etc. Different layers can be associated with different types of PDUs on which data can be sent. For example, a PDU associated with Layer 2 can be a frame, a PDU associated with Layer 3 can be a packet, and a PDU associated with Layer 4 can be a segment and / or a datagram, and so on.
[0053] In some cases, intermediate node 118 may be invisible in one layer but detectable in another. For example, intermediate node 118 may automatically forward PDUs sent in one layer but may actively manipulate and / or delay PDUs sent in another layer. Therefore, when intermediate node 118 is invisible in one layer, its presence can be identified by testing in other layers. In some implementations, in the first test, the first network node 104 and / or the first diagnostic system 120 may send a first diagnostic transmission (e.g., frames containing corrupted and uncorrupted data on Layer 2) through the first layer. If the presence of intermediate node 118 cannot be determined based on the first test, a second test can be performed. In the second test, the first network node 104 and / or the first diagnostic system 120 may send a second diagnostic transmission (e.g., packets containing corrupted and uncorrupted data on Layer 3) through the second layer. Depending on the circumstances, the second test may be used to identify the presence of intermediate node 118. In various examples, multiple tests may be performed using diagnostic transmissions on different layers until the presence of intermediate node 118 is identified. In the absence of intermediate node 118, multiple tests can be performed without confirming its existence. Furthermore, these techniques can be used to identify one or more layers on which intermediate node 118 is active, thereby identifying the type of intermediate node 18.
[0054] In some implementations, different types of tests can be performed in a specific order to identify the presence of intermediate node 118 in the most efficient way. For example, address-based testing can be performed using fewer communication resources than tests based on corrupted data, because the diagnostic and / or forwarding transmissions associated with address-based testing can include less data than those for tests based on corrupted data. Therefore, address-based testing can be performed as an initial screening technique, and if address-based testing is inconclusive (e.g., if intermediate node 118 cannot be detected by performing address-based testing), tests based on corrupted data can be performed after address-based testing. In various examples, label-based testing can be performed before other tests because label-based testing can be performed without injecting additional data traffic into internal network 102, thus saving resources of internal network 102. In some cases, some or all of the types of tests described herein can be performed consecutively to effectively identify the presence of intermediate node 118, regardless of whether intermediate node 118 cannot be detected using one or more types of tests.
[0055] Depending on the implementation, the first network node 104, the first diagnostic system 120, the second network node 106, and / or the second diagnostic system 122 can identify the presence of the intermediate node 118 based on diagnostic and forwarding transmissions. After identifying the presence of the intermediate node 118, the first network node 104, the first diagnostic system 120, the second network node 106, and / or the second diagnostic system 122 can update the topology based on the intermediate node 118. For example, the topology can be updated by sending a report indicative of the intermediate node 118 to the controller 108.
[0056] In some implementations, further transmission between the first network node 104 and the second network node 106 can be avoided to bypass the intermediate node 118. For example, after recognizing the presence of the intermediate node 118, the first network node 104 can route additional data transmission to the second network node 106 via one or more communication networks 112 without going through the intermediate node 118, or vice versa. In some cases, the controller 108 can route data traffic via one or more communication networks 112 without going through the intermediate node 118 based on an updated topology. For example, the controller 108 can modify the underlying network structure to avoid sending any data traffic to the intermediate node 118.
[0057] In certain situations, the presence of intermediate node 118 can be reported to a network administrator. For example, the network administrator could be a user associated with one or more user devices 116. First network node 104, second network node 106, and / or controller 108 can send alerts to one or more user devices 116 indicating the presence of intermediate node 118. The one or more user devices 116 can then output an alert to the network administrator. As a result, the network administrator can remove and / or otherwise disable intermediate node 118 within the internal network 102, thereby preventing disruption to the functionality of the internal network 102.
[0058] In some cases, intermediate node 118 may be known. For example, intermediate node 118 may be indicated within the existing network topology. However, the first network node 104 and / or the first diagnostic system 120 may send diagnostic transmissions, and the second network node 106 and / or the second diagnostic system 122 may receive and forward transmissions, to diagnose whether intermediate node 118 has malfunctioned. For example, diagnostic transmissions and forward transmissions may be compared to identify whether intermediate node 118 has malfunctioned by dropping packets. In some cases, the first network node 104 and / or the first diagnostic system 120, the second network node 106 and / or the second diagnostic system 122, or a combination thereof, may indicate how intermediate node 118 malfunctioned in a report to controller 108, load balancer 110, or (one or more) user equipment 116.
[0059] Figure 2A and 2B It shows in Figure 1 An example of signals transmitted between various components within environment 100 is shown. Figure 2A Example signaling 200 of a sending node for diagnosing intermediate nodes within a network is shown. As illustrated, signaling 200 can be executed between a first network node 104, a second network node 106, a controller 108, and an intermediate node 118 (see above). Figure 1 These nodes are described. In some examples, the functions performed by the first network node 104 may be performed by the first diagnostic system 120 described above, the functions performed by the second network node 106 may be performed by the second diagnostic system 122 described above, or a combination thereof.
[0060] First network node 104 may send diagnostic transmission 202 to second network node 106, which may be received by intermediate node 118. For example, diagnostic transmission 202 may be sent through intermediate node 118. Diagnostic transmission 202 may be addressed to second network node 106. For example, diagnostic transmission 202 may include one or more data packets addressed to second network node 106. In various cases, diagnostic transmission 202 may optionally include data that may be manipulated by intermediate node 118. In some cases, diagnostic transmission 202 may include data that can be used to infer whether intermediate node 118 is manipulating data forwarded by intermediate node 118. For example, diagnostic transmission 202 may include the MAC address of first network node 104, a mixture of corrupted and valid data, a mixture of malicious and valid data, multiple types of data, an indication of the length of the cable through which first network node 102 sends diagnostic transmission 202, iOAM tags, data traffic metrics, etc.
[0061] Intermediate node 118 may send forwarding transmission 204 to second network node 106. In various cases, intermediate node 118 may manipulate and / or modify data within diagnostic transmission 202. Forwarding transmission 204 may include at least some data from diagnostic transmission 202. For example, forwarding transmission 204 may include valid data included in diagnostic transmission 202. In some cases, forwarding transmission 204 may omit some data from the diagnostic transmission. For example, forwarding transmission 204 may omit the MAC address of the first network node 104, corrupted data, malicious data, at least some IOAM tags, etc. Depending on some implementations, forwarding transmission 204 may include data different from that included in diagnostic transmission 202. For example, forwarding transmission 204 may include the MAC address of intermediate node 118. In some cases, forwarding transmission 204 may be divided into different messages received by the second network node 106 at different times. For example, forwarding transmission 204 may include a first message carrying data of a first type from diagnostic transmission 202 and a second message carrying data of a second type from diagnostic transmission, wherein the first message and the second message are received by the second network node 106 at different times.
[0062] The second network node 106 may send an indication of forwarding transmission 206 to the first network node 104. In some cases, the indication of forwarding transmission 206 may include at least some data included in forwarding transmission 204. According to some implementations, the indication of forwarding transmission 206 may indicate additional details about forwarding transmission 204. For example, the indication of forwarding transmission 206 may indicate that the first message and the second message were received by the second network node 106 at different times.
[0063] The first network node 104 can identify the presence of the intermediate node 118 based on indications from diagnostic transmission 202 and / or forwarding transmission 206. The first network node 104 can send a node report 208 to the controller 108. The node report 208 can indicate the presence of the intermediate node 118. The controller 108 can use the node report 208 to update the network including the first network node 104 and the second network node 106 (e.g., referenced above). Figure 1 The network topology of the internal network 102 is described.
[0064] Although Figure 2ANot shown, but in some cases, the first network node 104 may suppress additional transmissions addressing to the second network node 106 via intermediate node 118. Furthermore, the first network node 104 may forward reports instructing intermediate node 118 to the second network node 106. Similarly, the second network node 106 may suppress additional transmissions addressing to the first network node 104 via intermediate node 118. These additional transmissions may alternatively be sent on alternative paths connecting the first network node 104 and the second network node 106.
[0065] Figure 2B An alternative example signaling 210 for a receiving node to diagnose intermediate nodes within a network is shown. As illustrated, signaling 210 can be executed between the first network node 104, the second network node 106, the controller 108, and the intermediate node 118 (see above). Figure 1 These nodes are described.
[0066] First network node 104 can send diagnostic transmission 212 to second network node 106, which can be received by intermediate node 118. For example, diagnostic transmission 212 can be sent through intermediate node 118. Diagnostic transmission 212 can be addressed to second network node 106. For example, diagnostic transmission 212 may include one or more data packets addressed to second network node 106. In various cases, diagnostic transmission 212 may optionally include data that may be manipulated by intermediate node 118. In some cases, diagnostic transmission 212 may include data that can be used to infer whether intermediate node 118 is manipulating data forwarded by intermediate node 118 to expose its presence. For example, diagnostic transmission 212 may include the MAC address of first network node 104, a mixture of corrupted and valid data, a mixture of malicious and valid data, multiple types of data, an indication of the length of the cable through which first network node 102 sends diagnostic transmission 212, iOAM tags, data traffic metrics, etc.
[0067] Intermediate node 118 may send forwarding transmission 214 to second network node 106. In various cases, intermediate node 118 may manipulate and / or modify data within diagnostic transmission 212. Forwarding transmission 214 may include at least some data from diagnostic transmission 202. For example, forwarding transmission 214 may include valid data included in diagnostic transmission 212. In some cases, forwarding transmission 214 may omit some data from the diagnostic transmission. For example, forwarding transmission 214 may omit the MAC address of the first network node 104, corrupted data, malicious data, cable length indications, etc. Depending on some implementations, forwarding transmission 214 may include data different from that included in diagnostic transmission 212. For example, forwarding transmission 214 may include the MAC address of intermediate node 118. In some cases, forwarding transmission 214 may be divided into different messages received by the second network node 106 at different times. For example, forwarding transmission 214 may include a first message carrying data of a first type from diagnostic transmission 212 and a second message carrying data of a second type from diagnostic transmission, wherein the first message and the second message are received by the second network node 106 at different times.
[0068] The first network node 104 may send an indication of diagnostic transmission 216 to the second network node 106. In some cases, the indication of diagnostic transmission 216 may include at least some data included in diagnostic transmission 212. According to some implementations, the indication of diagnostic transmission 216 may indicate additional details about diagnostic transmission 212. For example, the indication of diagnostic transmission 216 may indicate that the data contained in the first message and the data contained in the second message were sent simultaneously by the first network node 104.
[0069] The second network node 106 can identify the presence of the intermediate node 118 based on the indications of forwarding transmission 214 and / or diagnostic transmission 216. The second network node 106 can send a node report 218 to the controller 108. The node report 218 can indicate the presence of the intermediate node 118. The controller 108 can use the node report 218 to update the network including the first network node 104 and the second network node 106 (e.g., referenced above). Figure 1 The network topology of the internal network 102 is described.
[0070] although Figure 2BNot shown, but in some cases, the second network node 106 can suppress additional transmissions addressing to the first network node 104 via the intermediate node 118. Furthermore, the second network node 106 can forward reports instructing the intermediate node 118 to the first network node 104. Similarly, the first network node 104 can suppress additional transmissions addressing to the second network node 106 via the intermediate node 118. These additional transmissions can alternatively be sent on alternative paths connecting the first network node 104 and the second network node 106.
[0071] Figures 3A to 3G Various examples of diagnostic transports that can be used to diagnose intermediate nodes within a network are shown. Specifically, Figures 3A to 3E The diagnostic transmission 302 received by intermediate node 118 is shown (see above). Figure 1 (Description) and an example of forwarding transmission 304 sent by intermediate node 18.
[0072] Figure 3A Example signaling 300 using address-based diagnostic testing is shown. As illustrated, diagnostic transmission 302 may include a first address 306. In various cases, the first address 306 may be the sender of diagnostic transmission 302 (e.g., as referenced above). Figure 1 The address of the first network node 104 and / or the first diagnostic system 120 described. In various examples, the first address 306 may be the MAC address of the sender of the diagnostic transmission 302. In some cases, the first address 306 is indicated in both the header and payload of the diagnostic transmission 302.
[0073] Upon receiving diagnostic transmission 302, intermediate node 118 can modify the first address 306 in the header of diagnostic transmission 302 and forward the diagnostic transmission 302 with the modified header as forwarding transmission 304. The header of forwarding transmission 304 can indicate a second address 308 instead of the first address 306. The second address 308 can correspond to the address of intermediate node 118. For example, the second address 308 can be the MAC address of intermediate node 118. However, in some cases, intermediate node 118 may not modify the first address 306 in the payload of diagnostic transmission 302. In various examples, the second address 308 in the header of forwarding transmission 304 is compared with the first address 306 in the payload of forwarding transmission 304. Since the second address 308 instead of the first address 306 is present in the header of forwarding transmission 304, diagnostics can be performed on intermediate node 118. Figure 3A The signaling 300 shown can be used to identify intermediate node 118 when it is not visible to the corresponding network of layer 3 but is detectable in layer 2.
[0074] Although Figure 3A Although not shown in the diagram, in some implementations, the first address 306 may be omitted from the payload of diagnostic transmission 302 and the payload of forwarding transmission 304. For example, the destination of forwarding transmission 304 may diagnose the presence of intermediate node 118 by comparing the second address 308 in the header of forwarding transmission 304 with the first address 306 (which may have been pre-stored at the destination and / or received in a message separate from forwarding transmission 304). In some cases, the destination of forwarding transmission 304 may send a message to the source of diagnostic transmission 302 indicating the second address 308 received in the header of forwarding transmission 304, and the source may diagnose the presence of intermediate node 118 by comparing the second address 306 with its own first address 306. In various implementations of this disclosure, the presence of intermediate node 118 may be diagnosed based on the second address 308 in the header of forwarding transmission 304.
[0075] Figure 3B Example signaling 310 using diagnostic tests based on corrupted data is illustrated. As shown, diagnostic transmission 302 may include corrupted data 312 and valid data 314. As used herein, the term "valid data" may refer to uncorrupted data and / or non-malicious data. Upon receiving diagnostic transmission 302, intermediate node 118 may apply a security policy to automatically remove corrupted data 312, and intermediate node 118 may forward diagnostic transmission 302 as forwarding transmission 304. Forwarding transmission 304 may include valid data 314, but may omit corrupted data 312. Since corrupted data 312 is not present in forwarding transmission 304, diagnostics can be performed on intermediate node 118.
[0076] Depending on the implementation, the corrupted data 312 may include values that are selectively corrupted at different OSI layers. For example, the corrupted data 312 may include at least one corrupted value in layer 2, at least one corrupted value in layer 3, and so on. The intermediate node 118 may be configured to block and / or discard the corrupted data in some OSI layers (but not in others). Therefore, when the intermediate node 118 is not visible in at least one OSI layer, signaling 310 can be used to identify the intermediate node 118.
[0077] In some cases, diagnostic transmission 302 may include one or more packets (e.g., TCP synchronization (SYN) packets) on one or more public ports (e.g., port numbers 21, 23, 25, 80, 443, etc.) and one or more non-public ports (e.g., port numbers 4713, 37829, etc.). In some cases, non-public ports may be unofficial ports not registered with the Internet Corporation for Assigned Numbers (IANA). Packets sent on one or more public ports may be valid data 314, while packets sent on one or more non-public ports may be corrupted data 312.
[0078] According to some examples, diagnostic transmission 302 may include one or more acknowledgment (ACK) messages for unestablished TCP connections within the network. These ACK messages may be included in the corrupted data 312.
[0079] In some cases, the corrupted data 312 within diagnostic transmission 302 may include corrupted header fields. In some cases, diagnostic transmission 302 may include segments with corrupted header fields (e.g., TCP segments). For example, diagnostic transmission 302 may include corrupted TCP checksums. If segments including corrupted TCP checksums are excluded from forwarding transmission 304, intermediate node 118 can be identified as Layer 4 aware (e.g., intermediate node 118 may include a Layer 4 aware traffic filter). In some examples, diagnostic transmission 302 may include data packets with corrupted header fields (e.g., IP packets). For example, the TTL field in the header may reflect a value of "0". If data packets including invalid TTL fields are excluded from forwarding transmission 304, intermediate node 118 can be identified as Layer 3 aware (e.g., intermediate node 118 may include a Layer 3 traffic filter). Therefore, in these cases, the layer associated with intermediate node 118 can be further identified.
[0080] In some instances, the corrupted data 312 in diagnostic transmission 302 may include one or more packets containing corrupted Layer 2 frames (e.g., invalid Cyclic Redundancy Check (CRC)). If the corrupted Layer 2 frame is missed in forwarding transmission 304, intermediate node 118 can be identified as a Layer 2 node. Therefore, in these cases, in addition to identifying the presence and / or malfunction of intermediate node 118, the layer associated with intermediate node 118 can be further identified.
[0081] Figure 3CExample signaling 316 using diagnostic testing based on malicious data is shown. As illustrated, diagnostic transmission 302 may include malicious data 318 and valid data 314. In various implementations, malicious data 318 may include test files, such as EICAR test files and / or files associated with IPS test suites. Upon receiving diagnostic transmission 302, intermediate node 118 may automatically remove malicious data 318 and forward diagnostic transmission 302 as forwarding transmission 304. Forwarding transmission 304 may include valid data 314, but may omit malicious data 318. Since corrupted data 312 is not present in forwarding transmission 304, intermediate node 118 can be diagnosed.
[0082] Figure 3D Example signaling 320 using time-based diagnostic testing is illustrated. As shown, diagnostic transmission 304 may include first type data 322 and second type data 324. Upon receiving diagnostic transmission 302, intermediate node 118 may process the first type data 322 differently than the second type data 324. Intermediate node 118 may forward diagnostic transmission 302 as forwarding transmission 304. However, due to the difference in processing, intermediate node 118 may forward the first type data 322 at a different time than the second type data 324. For example, the first type data 322 may include passive TCP traffic (e.g., a passive file transfer protocol (FTP) data connection) of a specific size (e.g., 1000 bytes), and the second type data 324 may include HTTP / TCP traffic of that specific size. Intermediate node 118 may selectively process and / or buffer HTTP traffic, and may automatically forward TCP traffic without processing it.
[0083] In some cases, the first type of data 322 can be received immediately (e.g., as referenced above). Figure 1 The second network node 106 and / or the second diagnostic system 122 described herein receive data of the second type 324 at a second time. That is, the apparent "online time" (i.e., transmission time) of the first type of data 322 may differ from the apparent "online time" of the second type of data 324. Because the forwarding times of the first type of data 322 and the second type of data 324 are different, diagnostics can be performed on the intermediate node 118.
[0084] Figure 3E Example signaling 326 using a cable length-based diagnostic test is shown. As illustrated, diagnostic transmission 302 may include a first cable length 328. In various cases, the first cable length 328 may indicate on which diagnostic transmission 302 is sent (e.g., as referenced above). Figure 1The length of the cable (sent by the first network node 104 and / or the first diagnostic system 120) is described. For example, the first network node 104 may perform a cable length test toward the second network node 106, and thus can identify the cable length (if any) between the first network node 104 and the intermediate node 118. The cable length test may be performed, for example, by a time domain reflectometer (TDR) or polling (loopback) method within the first network node 104. In some cases, the first cable length 328 may be included in the payload of segments (e.g., TCP segments) and / or packets (e.g., IP packets) included in the diagnostic transmission 302.
[0085] Upon receiving diagnostic transmission 302, intermediate node 118 can forward the first cable length 328 within forwarding transmission 304. In various cases, forwarding transmission 304 is received by a node inferred to be adjacent to the first network node 104 (e.g., second network node 106). Second network node 106 can perform its own cable length test toward the first network node 104. Second network node 106 can identify a second cable length different from the first cable length 238. The second cable length can correspond to the cable length between second network node 106 and intermediate node 118. Intermediate node 118 can be identified due to the difference between the first cable length 328 and the second cable length. Although Figure 3E The diagram shows that the first cable length 328 is forwarded by intermediate node 118, but in some cases, the first cable length 328 may be via an alternative path through the network (e.g., through one or more communication networks 112, as referenced above). Figure 1 The data is transmitted from the first network node 104 to the second network node 106.
[0086] Figure 3F Example signaling 330 using tag-based traffic diagnostic testing is illustrated. In various cases, diagnostic transport 302 may include existing data traffic traversing the network and intermediate node 118. As shown, first data traffic 332 may be included within diagnostic transport 302. Furthermore, first data traffic 332 may include one or more first tags 334. The first tags 334 may indicate each packet within first data traffic 332. For example, the first tags 334 may include iOAM data indicating packets within first data traffic 332. In some cases, the first tags 334 may indicate a timestamp for each packet sent, hash values of various data fields at different OSI layers, etc.
[0087] Intermediate node 118 can modify the first data traffic 332 to generate a second data traffic 336. For example, the second data traffic 336 may miss one or more packets dropped by intermediate node 118 (e.g., due to the application of a security policy associated with intermediate node 118). The second data traffic 336 may include one or more second labels 338, which may be a subset of one or more first labels 334. That is, one or more second labels 338 may be an incomplete set of one or more first labels 334. A node receiving the second data traffic 336 can identify, based on one or more second labels 338, that at least some packets in the first data traffic 332 have been missed from the second data traffic 336. For example, iOAM data within one or more second labels 338 can be used to identify the absence of one or more packets in the second data traffic 336. By identifying that the second data traffic 336 of forwarding transmission 304 has missed at least some packets in the first data traffic 332 of diagnostic transmission 302, intermediate node 118 can be diagnosed.
[0088] Figure 3G Example signaling 340 using a diagnostic test based on large-scale traffic is illustrated. As shown, a diagnostic transport 302 may include one or more first metrics 342. The first metrics 342 may indicate data traffic previously sent from a first network node (e.g., first network node 104) to a second network node (e.g., second network node 106). In some cases, the first network node is the source of the diagnostic transport 302, and the diagnostic transport 302 addresses to the second network node. In some examples, the first metrics 342 may include multiple packets (e.g., HTTP packets) sent from the first network node to the second network node at specific intervals. The first metrics 342 may be included within the payload of segments and / or packets of the diagnostic transport 302.
[0089] Intermediate node 118 may forward one or more first metrics 342 in forwarding transmission 304. The entity receiving forwarding transmission 304 may compare one or more first metrics 342 with at least one second metric corresponding to data traffic previously received by the second network node from the first network node. In various cases, the comparison between one or more first metrics 342 and one or more second metrics may indicate that one or more packets in the data traffic were dropped during that time interval. By determining that one or more packets were not received by the second network node, intermediate node 118 can be diagnosed. Although Figure 3GIt is shown that one or more first metric 342s are forwarded by intermediate node 118, but in some cases, alternative paths connecting the first network node and the second network node can be used (e.g., via the above reference). Figure 1 The described path of one or more communication networks 112 is used to send one or more first metrics 342.
[0090] Figure 4 An example procedure 400 for diagnosing the presence and / or functional abnormalities of intermediate nodes within a network is shown. In various examples, procedure 400 may be derived from the above references. Figure 1 The second network node 106 and / or the second diagnostic system 122 described herein are executed.
[0091] At 402, an instruction for a diagnostic transmission originating from a network node can be received. The network node from which the diagnostic transmission originates can be the first network node 104 and / or the first diagnostic system 120, as referenced above. Figure 1 As described above. In some cases, the instruction may include communication via at least one communication network (e.g., as referenced above). Figure 1 The transmissions received by the described communication network(s) 112). In some cases, this indication may include transmissions received by intermediate nodes (e.g., as referenced above). Figure 1 The transmission forwarded by the intermediate node 118 described.
[0092] In various situations, diagnostic transports may selectively include data that could be manipulated by intermediate nodes. In some cases, diagnostic transports may include data that can be used to infer whether an intermediate node is manipulating data forwarded by that intermediate node. For example, diagnostic transports may include the MAC address of the node initiating the diagnostic transport, a mixture of corrupted and valid data, a mixture of malicious and valid data, multiple data types, an indication of the length of the cable on which the diagnostic transport is sent, iOAM tags, data traffic metrics, etc.
[0093] At 404, a forwarded transmission corresponding to the diagnostic transmission can be received. In various cases, intermediate nodes can manipulate and / or modify data within the diagnostic transmission. The forwarded transmission may include at least some data from the diagnostic transmission. For example, the forwarded transmission may include valid data included in the diagnostic transmission. In some cases, the forwarded transmission may omit certain data from the diagnostic transmission. For example, the forwarded transmission may omit the MAC address of the first network node, corrupted data, malicious data, at least some IOAM tags, etc. Depending on some implementations, the forwarded transmission may include data different from that included in the diagnostic transmission. For example, the forwarded transmission may include the MAC address of the intermediate node. In some cases, the forwarded transmission may be divided into different messages received by the second network node at different times. For example, the forwarded transmission may include a first message carrying a first type of data from the diagnostic transmission and a second message carrying a second type of data from the diagnostic transmission, wherein the first and second messages are received at different times. In some cases, the forwarded transmission includes cable length and / or data traffic metrics from the diagnostic transmission.
[0094] In 406, the presence and / or malfunction of intermediate nodes can be diagnosed based on diagnostic and / or forwarding transmissions. For example, the presence and / or malfunction of an intermediate node can be identified based on the difference between the MAC address indicated in the diagnostic transmission and the MAC address indicated in the forwarding transmission. In some cases, the presence and / or malfunction of an intermediate node can be identified based on the absence of corrupted data and / or malicious data in the forwarding transmission. In various cases, the presence and / or malfunction of an intermediate node can be identified based on the time difference between different data types received within the forwarding transmission. In some cases, the presence and / or malfunction of an intermediate node can be identified based on the difference between the cable length indicated in the forwarding transmission and the cable length calculated by the entity executing process 400. In various examples, the presence and / or malfunction of an intermediate node can be determined based on one or more iOAM tags within the forwarding transmission. According to some instances, the presence and / or malfunction of an intermediate node can be identified based on data traffic metrics within the forwarding transmission.
[0095] In some cases, the presence and / or malfunction of an intermediate node can be further reported to another node within the network. For example, the presence and / or malfunction can be reported to the network controller, which can then perform various functions to resolve the issue. In some cases, data traffic can be routed through the network in a manner that bypasses intermediate networks. In some examples, the presence and / or malfunction of an intermediate node can be communicated to the administrator, who can then manually resolve the issue.
[0096] Figure 5An example procedure 500 for identifying the presence of intermediate nodes within a network is shown. In various examples, procedure 500 can be referenced above. Figure 1 The second network node 106 and / or the second diagnostic system 122 described herein are executed.
[0097] At 502, instructions for diagnostic transmissions can be received from the network node. The network node from which the diagnostic transmissions originate can be the first network node 104 and / or the first diagnostic system 120, as referenced above. Figure 1 As described above. In some cases, this instruction may include communication via at least one communication network (e.g., as referenced above). Figure 1 The transmissions received by the described communication network(s) 112). In some cases, this indication may include transmissions received by intermediate nodes (e.g., as referenced above). Figure 1 The transmission forwarded by the intermediate node 118 described.
[0098] In various cases, diagnostic transports may selectively include data that could be manipulated by intermediate nodes (if present). In some cases, diagnostic transports may include data that can be used to infer whether an intermediate node is manipulating data forwarded by that intermediate node. For example, diagnostic transports may include the MAC address of the node initiating the diagnostic transport, a mixture of corrupted and valid data, a mixture of malicious and valid data, multiple data types, an indication of the length of the cable sending the diagnostic transport, iOAM tags, data traffic metrics, etc.
[0099] At 504, a forwarded transmission corresponding to the diagnostic transmission can be received. In various cases, intermediate nodes (if present) may manipulate and / or modify data within the diagnostic transmission. The forwarded transmission may include at least some data from the diagnostic transmission. For example, the forwarded transmission may include valid data included in the diagnostic transmission. In some cases, the forwarded transmission may omit certain data from the diagnostic transmission. For example, the forwarded transmission may omit the MAC address of the first network node, corrupted data, malicious data, at least some IOAM tags, etc. Depending on some implementations, the forwarded transmission may include data different from that included in the diagnostic transmission. For example, the forwarded transmission may include the MAC address of an intermediate node. In some cases, the forwarded transmission may be divided into different messages received by a second network node at different times. For example, the forwarded transmission may include a first message carrying data of a first type from the diagnostic transmission and a second message carrying data of a second type from the diagnostic transmission, wherein the first and second messages are received at different times. In some cases, the forwarded transmission includes data traffic metrics and / or cable lengths from the diagnostic transmission.
[0100] In section 506, diagnostic transports can be compared to forwarded transports. For example, one or more data fields in a diagnostic transport can be compared to one or more data fields in a forwarded transport. In some cases, packets in a diagnostic transport can be compared to one or more packets in a forwarded transport.
[0101] In step 508, process 500 includes determining whether to confirm the existence of an intermediate node. In various cases, the existence of an intermediate node can be confirmed based on the differences between the diagnostic transport and the forwarding transport. For example, if the MAC address in the diagnostic transport differs from the MAC address in the forwarding transport, the existence of an intermediate node can be confirmed. Otherwise, if the diagnostic transport and the forwarding transport include the same MAC address, the existence of an intermediate node is not confirmed.
[0102] In some examples, even though the diagnostic transmission contains corrupted and / or malicious data, the presence of an intermediate node can be confirmed based on the absence of corrupted and / or malicious data in the forwarded transmission. In some cases, only a portion of the corrupted and / or malicious data is excluded from the forwarded transmission. For example, a first portion of the corrupted and / or malicious data corresponding to the first OSI layer can be included in the forwarded transmission, while a second portion of the corrupted and / or malicious data corresponding to the second OSI layer can be excluded. Therefore, the activity of the intermediate node at the first OSI layer can be further confirmed. However, if the forwarded transmission includes corrupted and / or malicious data, the presence of the intermediate node may not be confirmed.
[0103] In some cases, the presence of an intermediate node can be confirmed based on the time difference in the reception of different types of data within a forwarding transmission. For example, a diagnostic transmission may include different types of data sent simultaneously (or within each other's threshold time intervals). However, if different types of data are received at different times (or at different times separated by a threshold time interval), the presence of an intermediate node can be confirmed. On the other hand, if different types of data are received simultaneously (e.g., within each other's threshold time intervals), the presence of an intermediate node may not be confirmed.
[0104] Depending on various examples, the presence of an intermediate node can be confirmed based on the difference between the tags included in the diagnostic transmission (e.g., iOAM tags) and the tags included in the forwarding transmission. In some cases, it can be identified that one or more packets included in the diagnostic transmission are not present in the forwarding transmission based on the tags in the diagnostic transmission, the tags in the forwarding transmission, or a combination thereof. However, if the tags indicate that all packets in the diagnostic transmission are included in the forwarding transmission, the presence of an intermediate node may not be confirmed.
[0105] If the existence of the intermediate node is confirmed at 508, then the existence of the intermediate node is reported at 510. For example, a report indicating the existence of the intermediate node can be generated and sent to the network controller (e.g., see reference above). Figure 1 The controller 108 described, another node within the corresponding network, or an external device (e.g., the one mentioned above in the reference) Figure 1 User equipment 116 is described. In some cases, the type of intermediate node (e.g., one or more OSI layers on which the intermediate node operates) may be further indicated in the report. In various cases, the report may be a transport.
[0106] If the existence of an intermediate node is not confirmed at 508, process 500 includes determining at 512 whether the final diagnostic test has been performed. In various cases, the entity performing process 500 may follow a protocol specifying a particular order of diagnostic tests. The protocol can be predetermined based on various factors. For example, diagnostic tests involving the injection of a minimum amount of data within the network may be performed before diagnostic tests involving the injection of a larger amount of data. In some cases, relatively simple diagnostic tests may be performed before more complex diagnostic tests (e.g., tests based on corrupted data and / or tests based on malicious data). At 512, it can be determined whether the final diagnostic test within the protocol has been followed.
[0107] If it is determined at 512 that the final diagnostic test has not yet been performed, process 500 proceeds to 514. At 514, additional diagnostic transmissions are received from the network node. In some cases, the entity executing process 500 may send a message requesting additional diagnostic transmissions. These diagnostic transmissions may correspond to the next diagnostic test within the protocol. Furthermore, after executing 514, based on the execution of the next diagnostic test, process 500 returns to 502.
[0108] However, if it is determined at 512 that the final diagnostic test has been performed, the process proceeds to 516. At 516, the absence of the intermediate node is reported. For example, a message indicating the absence of the intermediate node can be generated and sent to another network node and / or at least one external device. In some cases, the absence of the intermediate node can be reported to the network controller.
[0109] Figure 6 An example computer architecture is shown for a server computer 600 capable of executing program components for achieving the above-described functions. Figure 6The computer architecture shown illustrates conventional server computers, workstations, desktop computers, laptop computers, tablets, network devices, e-readers, smartphones, or other computing devices, and can be used to execute any of the software components presented herein. In some examples, server computer 600 may correspond to network nodes described herein (e.g., first network node 104 and / or second network node 106).
[0110] Computer 600 includes a baseboard 602 or “motherboard,” which is a printed circuit board that can connect a large number of components or devices via a system bus or other electrical communication path. In one illustrative configuration, one or more central processing units (“CPU”) 604 operate in conjunction with a chipset 606. CPU 604 may be a standard programmable processor that performs the arithmetic and logic operations necessary to perform the operation of computer 600.
[0111] The CPU 604 performs operations by manipulating switching elements that distinguish discrete physical states and change these physical states to transition from one physical state to the next. Switching elements typically include electronic circuitry (e.g., flip-flops) that holds one of two binary states and electronic circuitry that provides the output state based on a logical combination of the states of one or more other switching elements (e.g., logic gates). These basic switching elements can be combined to create more complex logic circuits, including registers, adders / subtractors, arithmetic logic units, floating-point units, and so on.
[0112] Chipset 606 provides an interface between CPU 604 and the remaining components and devices on substrate 602. Chipset 606 can provide an interface to random access memory (RAM) 608, which serves as main memory in computer 600. Chipset 606 can also provide an interface to a computer-readable storage medium (e.g., read-only memory (ROM) 610 or non-volatile RAM (NVRAM)) for storing basic routines that facilitate the startup of computer 600 and the transfer of information between various components and devices. ROM 610 or NVRAM can also store other software components necessary for the operation of computer 600 according to the configuration described herein.
[0113] Computer 600 can operate in a networked environment using logical connections to remote computing devices and computer systems via a network (e.g., network 612). Chipset 606 may include functionality for providing network connectivity via a network interface controller (NIC) 614, such as a Gigabit Ethernet adapter. NIC 614 enables computer 600 to connect to other computing devices via network 612. It should be understood that multiple NICs 614 may be present in computer 600, connecting computer 600 to other types of networks and remote computer systems. In some cases, NIC 614 may include at least one ingress port and / or at least one egress port.
[0114] Computer 600 can be connected to storage device 616, which provides non-volatile storage for the computer. Storage device 616 can store operating system 618, programs 620, and data, which are described in more detail herein. Storage device 616 can be connected to computer 600 via storage controller 622 connected to chipset 606. Storage device 616 can consist of one or more physical storage units. Storage controller 616 can interface with physical storage units via a serially connected Small Computer System Interface (SCSI) (SAS) interface, a Serial Advanced Technology Attachment (SATA) interface, a Fibre Channel (FC) interface, or other types of interfaces used for physically connecting the computer and physical storage units and transferring data between them.
[0115] Computer 600 can store data on storage device 616 by transforming the physical state of physical storage units to reflect the stored information. In different embodiments of this specification, the specific transformation of the physical state can depend on various factors. Examples of these factors may include, but are not limited to, the technology used to implement the physical storage units, whether storage device 616 is characterized as a primary storage device or a secondary storage device, etc.
[0116] For example, computer 600 can send instructions via storage controller 622 to change the magnetic properties of a specific location within a disk drive unit, the reflection or refraction properties of a specific location in an optical storage unit, or the electrical properties of a specific capacitor, transistor, or other discrete component in a solid-state storage unit, to store information in storage device 616. Other transformations of the physical medium are possible without departing from the scope and spirit of this specification; the examples provided above are merely for illustrative purposes. Computer 600 can also read information from storage device 616 by detecting the physical state or characteristics of one or more specific locations within the physical storage unit.
[0117] In addition to the aforementioned high-capacity storage device 616, computer 600 may also access other computer-readable storage media to store and retrieve information, such as program modules, data structures, or other data. Those skilled in the art will understand that computer-readable storage media are any available medium that provides non-transitory storage of data and can be accessed by computer 600. In some examples, operations performed by any network node described herein may be supported by one or more devices similar to computer 600. In other words, some or all of the operations performed by a network node may be performed by one or more computer devices 600 operating in a cloud-based configuration.
[0118] By way of example and not limitation, computer-readable storage media can include volatile and non-volatile, removable and non-removable media implemented in any method or technology. Computer-readable storage media include, but are not limited to, RAM, ROM, erasable programmable ROM (“EPROM”), electrically erasable programmable ROM (“EEPROM”), flash memory or other solid-state storage technologies, optical disc ROM (“CD-ROM”), digital versatile disc (“DVD”), high-definition DVD (“HD-DVD”), Blu-ray or other optical storage devices, cassette tape, magnetic tape, disk storage devices, or any other medium that can be used to store desired information in a non-transitory manner.
[0119] As described above, storage device 616 can store an operating system 618 for controlling the operation of computer 600. According to one embodiment, the operating system includes LINUX. TM Operating system. According to another embodiment, the operating system includes Windows from Microsoft Corporation of Redmond, Washington. TM SERVER operating system. According to a further embodiment, the operating system may include UNIX. TM One of the operating systems or its variants. It should be understood that other operating systems may also be used. Storage device 616 may store other systems, applications, and data used by computer 600.
[0120] In one embodiment, storage device 616 or other computer-readable storage medium is encoded with computer-executable instructions that, when loaded into computer 600, transform the computer from a general-purpose computing system into a special-purpose computer capable of implementing the embodiments described herein. As described above, these computer-executable instructions transform computer 600 by specifying how CPU 604 transitions between states. According to one embodiment, computer 600 can access a computer-readable storage medium storing computer-executable instructions that, when executed by computer 600, perform the instructions as described above. Figures 1 to 5The various processes described herein. The computer 600 may also include a computer-readable storage medium having instructions stored thereon for performing operations of any other computer implementation described herein.
[0121] like Figure 6 As shown, storage device 616 stores program 620 (program 620 may include one or more processes 624) and diagnostic system 626 (e.g., as shown in the reference above). Figure 1 The first diagnostic system 120 and / or the second diagnostic system 122 are described. Process 624 (one or more) may include instructions that, when executed by CPU 604 (one or more) of CPU 604, cause computer 600 and / or CPU 604 to perform one or more operations.
[0122] Computer 600 may also include one or more input / output controllers 628 for receiving and processing input from multiple input devices (e.g., keyboard, mouse, touchpad, touchscreen, electronic pen, or other types of input devices). Similarly, input / output controllers 628 may provide output to a display (e.g., computer monitor, flat panel display, digital projector), printer, or other types of output devices. It should be understood that computer 600 may not include... Figure 6 All components shown, and may include Figure 6 Other components not explicitly shown, or those that can be used with Figure 6 The architecture shown is completely different.
[0123] In summary, this disclosure describes techniques for diagnosing the presence or malfunction of a network node. In an example method, a first network node receives an indication of a diagnostic transmission originating from a second network node. The second network node also receives a forwarding transmission corresponding to the diagnostic transmission. Based on at least one of the indications from the forwarding transmission and the diagnostic transmission, the first network node diagnoses at least one of the presence of an intermediate node between the first and second network nodes and a malfunction of that intermediate node.
[0124] In some cases, one or more components may be referred to herein as “configured as,” “configurable as,” “operable / operable to,” “adapted / adaptable to,” “capable of,” “compliant / compliant,” etc. Those skilled in the art will recognize that, unless the context otherwise requires, these terms (e.g., “configured as”) may generally cover active state components and / or inactive state components and / or standby state components.
[0125] As used herein, the term "based on" may be synonymous with "at least partially based on" and "at least partially based on". As used herein, the terms "comprising / including / having" and "including / containing" and their equivalents may be used interchangeably. An apparatus, system, or method "comprising A, B, and C" includes A, B, and C, but may also include other components (e.g., D). That is, the apparatus, system, or method is not limited to components A, B, and C.
[0126] While the invention has been described with reference to specific examples, it should be understood that the scope of the invention is not limited to these specific examples. Since other modifications and alterations to suit specific operational requirements and environments will be apparent to those skilled in the art, the invention is not to be considered limited to the examples chosen for the purposes of disclosure, and covers all modifications and alterations that do not constitute a departure from the true spirit and scope of the invention.
[0127] Although this application describes embodiments with specific structural features and / or methodological actions, it should be understood that the claims are not necessarily limited to the specific features or actions described. Rather, the specific features and actions are merely illustrative embodiments falling within the scope of the claims of this application.
Claims
1. A method for diagnosing an intermediate node, comprising: receiving, by a first network node, an indication of a diagnostic transmission originating from a second network node; receiving, by the first network node, a forwarded transmission corresponding to the diagnostic transmission; and diagnosing, by the first network node, at least one of a presence of an intermediate node between the first network node and the second network node and a functional anomaly of the intermediate node based on the forwarded transmission and the indication of the diagnostic transmission, wherein a header of the diagnostic transmission comprises a first address and a payload of the diagnostic transmission comprises the first address, wherein a header of the forwarded transmission comprises a second address and a payload of the forwarded transmission comprises the first address, and wherein diagnosing at least one of the presence of the intermediate node and the functional anomaly of the intermediate node comprises determining that the first address in the payload of the forwarded transmission is different from the second address in the header of the forwarded transmission.
2. The method of claim 1, further comprising: sending a report to a network controller indicating at least one of the presence of the intermediate node and the functional anomaly of the intermediate node between the first network node and the second network node. the diagnostic transmission comprises corrupted data and uncorrupted data, 3. The method of claim 1, wherein, wherein the forwarded transmission comprises the uncorrupted data and misses the corrupted data, and wherein diagnosing at least one of the presence of the intermediate node and the functional anomaly of the intermediate node comprises determining that the forwarded transmission misses the corrupted data. the corrupted data is first corrupted data associated with a first layer, 4. The method of claim 3, wherein, wherein the diagnostic transmission further comprises second corrupted data associated with a second layer, the second layer being different from the first layer, the forwarded transmission further comprises the second corrupted data, and wherein the method further comprises: determining, based on an absence of the first corrupted data in the forwarded transmission, that the intermediate node is active in the first layer; and determining, based on a presence of the second corrupted data in the forwarded transmission, that the intermediate node is not visible in the second layer. the diagnostic transmission comprises a first packet and a second packet, the first packet comprising inert malicious data, the second packet comprising non-malicious data, 5. The method of claim 1, wherein, wherein the forwarded transmission comprises the second packet and misses the first packet, and wherein diagnosing at least one of the presence of the intermediate node and the functional anomaly of the intermediate node comprises determining that the forwarded transmission misses the first packet. the diagnostic transmission comprises a first type of data and a second type of data, 6. The method of claim 1, wherein, wherein the forwarded transmission comprises the first type of data and the second type of data, and wherein diagnosing at least one of the presence of the intermediate node and the functional anomaly of the intermediate node comprises determining that a first time at which the first type of data in the forwarded transmission is received is different from a second time at which the second type of data in the forwarded transmission is received. 7. The method of any one of claims 1 to 6, wherein, the diagnostic transmission includes at least one first packet and an in-band operations, maintenance, and management (iOAM) tag indicating a first content of the at least one first packet, wherein the forwarding transmission includes at least one second packet and the iOAM tag, and wherein identifying the presence of the intermediate node is based at least in part on the iOAM tag in the forwarding transmission indicating the first content different from a second content of the at least one second packet.
8. A system for diagnosing an intermediate node, comprising: at least one processor; and one or more non-transitory media storing instructions that, when executed by the system, cause the system to perform operations comprising: receiving, by a first network node, an indication of a diagnostic transmission originating from a second network node; receiving, by the first network node, a forwarding transmission corresponding to the diagnostic transmission; and based on the forwarding transmission and the indication of the diagnostic transmission, identifying a presence of an intermediate node between the first network node and the second network node, wherein a header of the diagnostic transmission includes a first address and a payload of the diagnostic transmission includes the first address, wherein a header of the forwarding transmission includes a second address and a payload of the forwarding transmission includes the first address, and wherein diagnosing at least one of the presence of the intermediate node and a functional abnormality of the intermediate node includes determining that the first address in the payload of the forwarding transmission is different from the second address in the header of the forwarding transmission.
9. The system of claim 8, wherein, the operations further comprising: sending, to a network controller, a report indicating the presence of the intermediate node between the first network node and the second network node.
10. The system of claim 8, wherein, the diagnostic transmission includes corrupted data and uncorrupted data, wherein the forwarding transmission includes the uncorrupted data and misses the corrupted data, and wherein identifying the presence of the intermediate node includes determining that the forwarding transmission misses the corrupted data.
11. The system of claim 10, the diagnostic transmission being a first diagnostic transmission, the forwarding transmission being a first forwarding transmission, the corrupted data being first corrupted data, and the uncorrupted data being first uncorrupted data, the operations further comprising: receiving, by the first network node, an indication of a second diagnostic transmission originating from the second network node, the first diagnostic transmission being associated with a first layer different from a second layer associated with the second diagnostic transmission, the second diagnostic transmission including second corrupted data and second uncorrupted data; receiving, by the first network node, a second forwarding transmission corresponding to the second diagnostic transmission; determining that the second forwarding transmission includes the second corrupted data and the second uncorrupted data; and in response to determining that the second forwarding transmission includes the second corrupted data and the second uncorrupted data, sending, by the first network node, a request for the indication of the first diagnostic transmission.
12. The system of claim 8, wherein, the diagnostic transmission including benign malicious data and non-malicious data, wherein the forwarded transmission includes the non-malicious data and misses the benign malicious data, and wherein identifying the presence of the intermediate node includes determining that the forwarded transmission misses the benign malicious data.
13. The system of claim 8, wherein, the diagnostic transmission includes a first type of data and a second type of data, wherein the forwarded transmission includes the first type of data and the second type of data, and wherein identifying the presence of the intermediate node includes determining that a first time at which the first type of data in the forwarded transmission is received is different from a second time at which the second type of data in the forwarded transmission is received.
14. The system of claim 8, wherein, the diagnostic transmission includes at least one first packet, at least one first in-band operations, administration, and maintenance (iOAM) tag associated with the at least one first packet, at least one second packet, and at least one second iOAM tag associated with the at least one second packet, wherein the forwarded transmission includes the at least one first packet and the at least one first iOAM tag, and misses the at least one second packet and the at least one second iOAM tag, and wherein identifying the presence of the intermediate node includes identifying that the forwarded transmission misses the at least one first packet by analyzing the at least one second iOAM tag.
15. The system of claim 8, wherein, the operations further include: identifying, by the first network node, a first length of a first cable connecting the first network node to the intermediate node, wherein the forwarded transmission indicates a second length of a second cable connecting the second network node to the intermediate node, and wherein identifying the presence of the intermediate node includes determining that the first length is different from the second length.
16. The system of any one of claims 8 to 15, wherein, the operations further include: receiving, by the first network node, one or more first packets transmitted by the second network node during a time interval, wherein the forwarded transmission indicates at least one metric indicating second packets transmitted by the second network node to the first network node in the time interval, the second packets including the one or more first packets and one or more third packets, and wherein identifying the presence of the intermediate node includes determining, based on the at least one metric, that the one or more first packets miss the one or more third packets.
17. An apparatus for diagnosing an intermediate node, comprising: means for receiving, by a first network node, an indication of a diagnostic transmission originating from a second network node; means for receiving, by the first network node, a forwarded transmission corresponding to the diagnostic transmission; and means for diagnosing, by the first network node, at least one of a presence of an intermediate node between the first network node and the second network node and a functional anomaly of the intermediate node based on the forwarded transmission and the indication of the diagnostic transmission, wherein a header of the diagnostic transmission includes a first address and a payload of the diagnostic transmission includes the first address, wherein the header of the forwarded transmission comprises a second address and the payload of the forwarded transmission comprises the first address, and wherein diagnosing at least one of the presence of the intermediate node and a functional anomaly of the intermediate node comprises determining that the first address in the payload of the forwarded transmission is different from the second address in the header of the forwarded transmission.
18. The apparatus of claim 17, further comprising means for implementing the method of any one of claims 2 to 7.
19. A computer readable medium comprising instructions, which, when executed by a computer, cause the computer to carry out the steps of the method of any one of claims 1 to 7.
Citation Information
Patent Citations
Purposely corrupted packet for connection information
US20170034003A1