A Link Precision Expansion Analysis Method and Device Based on SNMP and Netflow
By combining SNMP and Netflow technology in network expansion analysis, the inter-salad traffic components and link utilization rate are calculated, and the problems of low data acquisition frequency and inability to clearly evaluate expansion in the existing technology are solved, achieving more accurate and real-time network expansion analysis.
Patent Information
- Application Number
- CN202211584507.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-09
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-12-09
AI Technical Summary
The prior art has problems in network capacity expansion with low data acquisition frequency, relying on basic data configuration, and being unable to clearly evaluate capacity expansion.
The precise link expansion analysis method based on SNMP and Netflow is adopted, and the traffic component data between provinces is obtained through Netflow traffic acquisition, and the shortest path between provinces is calculated in combination with IGP, and direct connection and expansion suggestions are given based on the traffic component data and link utilization.
It realizes more accurate and real-time network capacity expansion analysis, and can give specific suggestions based on traffic components and link utilization, improving the efficiency and accuracy of network capacity expansion.
Smart Images

Figure CN115967630B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network expansion, and in particular to a method and device for accurate link expansion analysis based on SNMP and Netflow. Background Art
[0002] Traditional network monitoring methods mostly use the pull mode for the collector to obtain monitoring data, and the data sampling frequency is relatively low, generally sampling once every 5 minutes. Telemetry is a technology for remotely collecting data from physical or virtual devices at high speed. The device actively sends device data information to the collector through the push mode, providing a more real-time and high-speed data collection function. High-frequency sampling technologies represented by telemetry can achieve high-frequency sampling technologies at intervals of 0.1 second, 1 second, 5 seconds, 10 seconds, etc. Telemetry devices include collectors, analyzers, and controllers, among which collectors and analyzers are often integrated into network controllers or network managers.
[0003] The prior art relies relatively heavily on basic data configurations: node configuration data, regular expressions for provincial core devices, etc., and it is necessary to ensure that the basic data configurations are correct.
[0004] In addition, the prior art cannot clearly evaluate expansion, and can only deduce expansion suggestions based on busy-hour traffic data or the latest traffic data.
[0005] A regular expression, also known as a rule expression (Regular Expression, often abbreviated as regex, regexp, or RE in code), is a text pattern that includes ordinary characters (for example, letters between a and z) and special characters (referred to as "meta-characters"), and is a concept in computer science. Regular expressions use a single string to describe and match a series of strings that match a certain syntactic rule, and are usually used to retrieve and replace text that conforms to a certain pattern (rule). Summary of the Invention
[0006] To solve the problems existing in the prior art, the present invention provides a method and device for accurate link expansion analysis based on SNMP and Netflow. By collecting Netflow traffic, traffic component data between provinces is obtained. The shortest path between provinces is calculated through IGP based on provincial core devices, and relevant link data of the inter-provincial path is obtained according to the inter-provincial relay link. Suggestions such as recommended direct connection and recommended expansion are given based on the traffic component data and link utilization conditions.
[0007] To achieve the above object, the present invention adopts the following technical solutions:
[0008] In an embodiment of the present invention, a method for accurate link capacity expansion analysis based on SNMP and Netflow is proposed. The method includes:
[0009] S01. Obtain configuration data such as regular expressions of each province and its provincial core devices in the plane according to the selected plane;
[0010] S02. Obtain the provincial core devices according to the regular expressions of the provincial core devices, and then obtain the inter-provincial relay link data;
[0011] S03. Obtain the traffic component data between provinces through Netflow data collection and analysis;
[0012] S04. Calculate the path information from province to province according to the shortest path of the provincial core devices. The shortest path can be calculated by the Dijkstra algorithm according to the routing, neighbor, Metric and other information collected by IGP (Interior Gateway Protocol);
[0013] S05. If the average flow velocity of the traffic components calculated in S03 exceeds the threshold and the connection between provinces is not direct, that is, the inter-provincial path in S04 is not direct, give a direct connection suggestion;
[0014] S06. Obtain the traffic distribution of the links passed from province to province and the traffic utilization rate of the links passed by the province according to the path information from province to province, the average flow velocity of the traffic components and the inter-provincial relay circuit data;
[0015] S07. For the case where the utilization rate of the relay link calculated in S06 exceeds the utilization rate threshold, give a capacity expansion suggestion in the source province and the target province of the link.
[0016] Furthermore, the configuration data in S01 is obtained from the plane configuration data and the node province configuration data, and this configuration data is manually maintained data.
[0017] Furthermore, S02 includes:
[0018] S021. Match according to the collected device names. If the regular expressions of the provincial core devices are satisfied, they are the provincial core devices;
[0019] S022. According to the collected circuit data, the link with both ends being provincial core devices is the inter-provincial relay link;
[0020] Furthermore, the inter-provincial relay link data in S022 includes: circuit identifier, local device identifier, peer device identifier, local port name, peer port name, Metric, bandwidth.
[0021] Furthermore, S03 includes:
[0022] S031. The basic objects and their object types (networks) are defined in advance by means of address segment ranges, BGP AS PATH regular expressions, BGP COMMUNITIES, etc.;
[0023] S032. Netflow collection tags the traffic according to the custom-defined basic objects to obtain information such as device identification, port name, collection time, source network, target network, target address segment, packet speed, etc.;
[0024] S033. The source province and the destination province can be obtained based on the source network and the target network;
[0025] S034. The traffic information between the relevant networks belonging to the source province and the relevant networks belonging to the destination province is the traffic component between provinces.
[0026] Further, the traffic distribution of the provincial path link in S06 is: the total traffic from province to province / the number of hops, and the total traffic is evenly distributed among provinces.
[0027] For example, the inter-provincial path from Beijing to Shanghai is Beijing -> Anhui -> Shanghai. The total traffic from Beijing to Shanghai is calculated, and the traffic component of 120 Gbps from Beijing to Shanghai is evenly distributed into two path segments: Beijing -> Anhui and Anhui -> Shanghai.
[0028] The calculation method of the traffic utilization rate of the inter-provincial link is: traffic / bandwidth.
[0029] For example, it is known that the bandwidth of the relay link from Beijing to Anhui is 100 G. The average flow rate of the single-segment traffic of 60 Gbps is divided by the link bandwidth of 100 G to obtain a traffic utilization rate of 60%.
[0030] The inter-provincial relay link is the link between provincial core devices. The shortest path between provincial core devices is equivalent to the combination of multiple path segments of the inter-provincial relay link. For example, there are inter-provincial relay links between Beijing and Guangzhou, and between Beijing and Fujian. There are also inter-provincial relay links between Guangzhou and Shanghai, and between Fujian and Shanghai. There is no inter-provincial relay link between Beijing and Shanghai. When calculating the path from the Beijing device to the Shanghai device, it can be reached through Fujian and Guangzhou, but the Metric value of the inter-provincial relay circuit of Fujian is larger than that of the inter-provincial relay circuit of Guangzhou. Therefore, the shortest path from Beijing to Shanghai is Beijing -> Guangzhou -> Shanghai.
[0031] The link data of the inter-provincial path includes the number of hops passed, the start point, end point, circuit identification, bandwidth, metric, etc. of the inter-provincial relay link.
[0032] In an embodiment of the present invention, a link precise capacity expansion analysis device based on SNMP and Netflow is also proposed. The device includes:
[0033] The configuration data acquisition module acquires configuration data such as regular expressions of provinces and their provincial core devices in the plane according to the selected plane;
[0034] The relay link data acquisition module obtains the provincial core device according to the provincial core device regular expression, and then obtains the inter-provincial relay link data;
[0035] The traffic component acquisition module collects and analyzes data through Netflow to obtain traffic component data between provinces;
[0036] The shortest path calculation module calculates the shortest path from province to province based on the provincial core device;
[0037] The direct connection suggestion module gives a direct connection suggestion based on the flow component data calculated in the flow component acquisition module, if the average flow rate of the flow component exceeds a threshold and the province to province is not directly connected;
[0038] The traffic distribution and utilization acquisition module obtains the traffic distribution of the province-to-province link and the traffic utilization of the province-to-province link based on the province-to-province path information, the average flow rate of the traffic components and the inter-province relay circuit data;
[0039] The capacity expansion suggestion module gives capacity expansion suggestions in the source province and the target province of the link when the relay link calculated in the traffic distribution and utilization acquisition module exceeds the utilization threshold.
[0040] Furthermore, the method for acquiring configuration data in the configuration data acquisition module is: acquiring from plane configuration data and node province configuration data, and the configuration data is manually maintained data.
[0041] Furthermore, the relay link data acquisition module includes:
[0042] The core device judgment module matches the device name obtained by the collection. If the device name satisfies the provincial core device regular expression, it is the provincial core device.
[0043] The relay link acquisition module, based on the collected circuit data, determines that the link whose dual-end devices are both provincial core devices is an inter-provincial relay link.
[0044] Furthermore, the inter-provincial relay link data in the relay link acquisition module includes: circuit identification, local device identification, opposite device identification, local port name, opposite port name, metric, and bandwidth.
[0045] Furthermore, the flow component acquisition module includes:
[0046] Define the module, and define the basic object and its object type first through address segment range, BGPASPATH regular expression, BGPCOMMUNITY, etc.
[0047] The Netflow collection module tags the traffic according to the custom basic object in Netflow collection to obtain information such as device identification, port name, collection time, source network, target network, target address segment, and packet speed;
[0048] The province belonging acquisition module can obtain the source province and the destination province according to the source network and the target network;
[0049] The traffic component acquisition module: The traffic information between the relevant network belonging to the source province and the relevant network belonging to the target province is the traffic component between provinces.
[0050] Furthermore, in the traffic distribution and utilization rate acquisition module, the traffic distribution of the provincial path link is: the total traffic from province to province / the number of hops, and the total traffic is evenly distributed among provinces;
[0051] The calculation method of the traffic utilization rate of the inter-provincial link is: traffic / bandwidth.
[0052] In an embodiment of the present invention, a computer device is further proposed, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the foregoing link precise expansion analysis method based on SNMP and Netflow is implemented.
[0053] In an embodiment of the present invention, a computer-readable storage medium is further proposed. The computer-readable storage medium stores a computer program for executing the link precise expansion analysis method based on SNMP and Netflow.
[0054] Beneficial effects:
[0055] The present invention intuitively displays data such as inter-provincial relay link traffic, metric values, and bandwidth; the present invention marks the provinces that need to expand capacity or are recommended for direct connection with stars for subsequent processing; the present invention intuitively displays the mutual access traffic and access paths of each province. Description of the Drawings
[0056] Figure 1 It is a schematic flowchart of the link precise expansion analysis method based on SNMP and Netflow of the present invention;
[0057] Figure 2 It is a schematic flowchart of the embodiment of the present invention;
[0058] Figure 3 It is a schematic structural diagram of the link precise expansion analysis device based on SNMP and Netflow of the present invention;
[0059] Figure 4It is a schematic structural diagram of a computer device according to an embodiment of the present invention. Detailed implementation manners
[0060] The principles and spirit of the present invention will be described below with reference to several exemplary implementation manners. It should be understood that these implementation manners are provided only to enable those skilled in the art to better understand and then implement the present invention, rather than limiting the scope of the present invention in any way. On the contrary, these implementation manners are provided to make the present disclosure more thorough and complete, and to be able to fully convey the scope of the present disclosure to those skilled in the art.
[0061] Those skilled in the art know that the implementation manners of the present invention can be implemented as a system, a device, an equipment, a method or a computer program product. Therefore, the present disclosure can be specifically implemented in the following forms, namely: completely hardware, completely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.
[0062] Terms related to the present invention and their Chinese explanations:
[0063] Metric: multi-exit-discriminator, also called MED attribute, which has the following characteristics:
[0064] First of all, it is an attribute that affects the route selection of other routers, rather than itself;
[0065] This attribute can be transmitted between different ASs (weight is only valid for the local router; local pre is transmitted within the local AS);
[0066] This attribute can only affect the path selection when entering an AS. When the update of the same network is transmitted to the next AS, the metric will be reset to 0, that is, this attribute can only be transmitted for one hop;
[0067] The smaller the metric value, the more preferred the path;
[0068] By default, a router can only select between paths from different EBGP neighbors of the same AS according to the metric. If its EBGP neighbors are from different ASs, it cannot make a selection;
[0069] NetFlow: NetFlow is a network monitoring function that can collect the number and information of IP packets entering and leaving the network interface. It was first developed by Cisco and is applied to products such as routers and switches. By analyzing the information collected by NetFlow, network administrators can know the source and destination of the packets, the types of network services, and the reasons for network congestion.
[0070] NetFlow data collection is targeted at the NetFlow data sent by routers. The NetFlow data collection software can be used to store it on a server for further processing using various NetFlow data analysis tools. Cisco provides Cisco NetFlow Collector (NFC) to collect NetFlow data, and many other manufacturers also provide similar collection software.
[0071] SNMP: Simple Network Management Protocol. It can collect information such as the CPU, memory, and logs of network devices, but the disadvantage is that it cannot collect network data traffic and cannot judge link congestion. This Pull-based mode can no longer meet the requirements of today's cloud data centers. After different manufacturers configure the SNMP protocol, they can obtain information related to switch ports, such as ifIndex port index number, ifDescr port description, ifType port type, ipSpeed port speed, ifMtu maximum transmission packet byte count, etc.
[0072] Dijkstra algorithm: The Dijkstra algorithm is a typical single-source shortest path algorithm used to calculate the shortest paths from one node to all other nodes. Its main feature is to expand layer by layer outward from the starting point until the end point is reached. The Dijkstra algorithm adopts the strategy of the greedy algorithm, dividing all vertices into two sets: marked vertices and unmarked vertices. Starting from the starting point, it continuously searches for the vertex with the shortest path distance from the starting point among the unmarked vertices and marks it until all vertices are marked. It should be noted that this method cannot handle graphs with negative-weight edges. The IGP shortest path mentioned in the text is the shortest path calculated based on the IGP neighbor METRIC value attribute as the path length.
[0073] According to an embodiment of the present invention, a method and device for accurate link capacity expansion analysis based on SNMP and Netflow are proposed. Provincial inter-provincial traffic component data is obtained through Netflow traffic collection. The shortest paths between provinces are obtained by calculating through the IGP of provincial core devices. Relevant link data of the inter-provincial paths are obtained based on the inter-provincial relay links. Suggestions such as recommended direct connection and recommended capacity expansion are given based on the traffic component data and link utilization conditions.
[0074] Next, with reference to several representative embodiments of the present invention, the principles and spirit of the present invention will be elaborated in detail.
[0075] As Figure 1 shown, the method includes:
[0076] S01. Obtain configuration data such as regular expressions of each province and its provincial core devices within the selected plane according to the selected plane;
[0077] S02, obtaining the provincial core device according to the provincial core device regular expression, and then obtaining the inter-provincial relay link data;
[0078] S03, obtain traffic component data between provinces through Netflow collection and analysis data;
[0079] S04. Calculate the shortest path between provinces based on the provincial core device, and obtain the path information between provinces. Calculate the shortest path using the Dijkstra algorithm based on the routing, neighbor, metric and other information collected by the IGP (Interior Gateway Protocol).
[0080] S05. According to the traffic component data calculated in S03, the average flow rate of the traffic component exceeds the threshold, and the province to province is not directly connected, that is, the inter-provincial path in S04 is not direct, and a direct connection suggestion is given;
[0081] S06. According to the province-to-province path information, the average flow rate of the traffic components and the inter-province relay circuit data, the flow distribution of the province-to-province path link and the flow utilization rate of the province path link are obtained.
[0082] S07. When the relay link calculated in step 6 exceeds the utilization threshold, a capacity expansion suggestion is given in the source province and the target province of the link.
[0083] The configuration data in S01 is obtained from the plane configuration data and the node province configuration data, and the configuration data is manually maintained data.
[0084] The S02 includes:
[0085] S021. Match the device name obtained by the collection. If the device name meets the provincial core device regular expression, the device is a provincial core device.
[0086] S022. According to the collected circuit data, the link where both end devices are provincial core devices is an inter-provincial relay link;
[0087] The inter-provincial relay link data in S022 includes: circuit identification, local device identification, opposite device identification, local port name, opposite port name, metric, and bandwidth.
[0088] The S03 includes:
[0089] S031. The basic object and its object type (network) will be defined first through address segment range, BGPASPATH regular expression, BGPCOMMUNITY, etc.
[0090] S032. The Netflow collection tags the traffic according to a custom basic object to obtain information such as device identification, port name, collection time, source network, target network, target address segment, packet speed, etc.
[0091] S033. The source province and the destination province can be obtained based on the source network and the target network.
[0092] S034. The traffic information between the relevant networks belonging to the source province and the relevant networks belonging to the target province is the traffic component between provinces.
[0093] In S06, the traffic distribution of the provincial path link is: the total traffic from province to province / the number of hops, and the total traffic is evenly distributed among provinces.
[0094] For example, the inter-provincial path from Beijing to Shanghai is Beijing -> Anhui -> Shanghai. The total traffic from Beijing to Shanghai is calculated, and the traffic component of 120 Gbps from Beijing to Shanghai is evenly distributed to the two paths of Beijing -> Anhui and Anhui -> Shanghai.
[0095] The calculation method of the traffic utilization rate of the inter-provincial link is: traffic / bandwidth.
[0096] For example, it is known that the bandwidth of the relay link from Beijing to Anhui is 100 G. The average flow rate of a single segment of traffic, 60 Gbps, divided by the link bandwidth of 100 G gives a traffic utilization rate of 60%.
[0097] The inter-provincial relay link is the link between provincial core devices. The shortest path between provincial core devices is equivalent to the combination of multiple segments of the inter-provincial relay link. For example, there are inter-provincial relay links between Beijing and Guangzhou, and between Beijing and Fujian. There are also inter-provincial relay links between Guangzhou and Shanghai, and between Fujian and Shanghai. There is no inter-provincial relay link between Beijing and Shanghai. When calculating the path from a Beijing device to a Shanghai device, it can be reached through Fujian and Guangzhou, but the Metric value of the inter-provincial relay circuit of Fujian is larger than that of the inter-provincial relay circuit of Guangzhou. Therefore, the shortest path from Beijing to Shanghai is Beijing -> Guangzhou -> Shanghai.
[0098] The link data of the inter-provincial path includes the number of hops passed, and the start point, end point, circuit identification, bandwidth, metric, etc. of the inter-provincial relay link.
[0099] It should be noted that although the operations of the method of the present invention are described in a specific order in the above embodiments and the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.
[0100] To more clearly explain the above-mentioned method for accurate link capacity expansion analysis based on SNMP and Netflow, a specific embodiment will be described below. However, it should be noted that this embodiment is only for better explaining the present invention and does not constitute an improper limitation to the present invention.
[0101] As Figure 2 shown, S01, input plane, obtain plane information from the query plane configuration data, and take the query of the new plane I as an example later. The plane configuration data is as shown in Table 1 below:
[0102]
[0103]
[0104] Table 1
[0105] The input plane is equivalent to the interface input parameter. The system knows that the user wants to view the capacity expansion suggestions for each province in this plane. If there is no input, the capacity expansion suggestions for each plane are generated according to different planes.
[0106] S02. Query the node configuration data information according to the plane code, and obtain data such as each province and its provincial core device regular expression in the plane, as shown in Table 2 below.
[0107] The plane code is a unique identifier for the custom plane and cannot be repeated. The plane code is obtained by querying in the node configuration data, and the restricted plane code is pnew-1 obtained by querying in the first step.
[0108] The data in Table 2 is as follows:
[0109]
[0110]
[0111]
[0112] Table 2
[0113] Taking Beijing as an example, the regular expression of the backbone core device of Beijing in the new plane can be obtained: ^
[0114] BJ-BJ-.*-C-5.
[0115] S03. Obtain the inter-provincial relay link data according to the provincial core device regular expression. The search method is: first obtain the provincial core device data according to the provincial core device regular expression, and the link in the circuit table where both ends of the device are provincial core devices is the inter-provincial relay link.
[0116] 1) Taking Beijing as an example, search for the core device according to the regular expression: 202.97.31.104, as shown in Table 3 below:
[0117]
[0118] Table 3
[0119] 2) Find the relay links from Beijing to each province in the new plane based on the core devices. Taking the target province as Shanghai as an example, calculate the relay links from Beijing to Shanghai. First, calculate the backbone core device of Shanghai in the new plane according to the logic of finding the backbone core device: 202.97.31.16. Obtain the relay links through dual-end devices (i.e., the circuits with dual-end devices being the backbone core devices of Beijing and Shanghai): five relay links, namely CIRbmo6w, CIRbmo7n, CIRbwo5q, CIRbvqcb, and CIRbvqc6, with a bandwidth of 100G each, as shown in Table 4 below:
[0120]
[0121]
[0122] Table 4
[0123] S04. Obtain the data of the outgoing and incoming traffic components from Beijing to Shanghai through Netflow collection and analysis. If calculating the outgoing traffic from Beijing to Shanghai, then count the aggregated data of the traffic components of Shanghai collected on the backbone devices of Beijing and their related ports; if calculating the incoming traffic from Beijing to Shanghai, then count the aggregated data of the traffic components of Shanghai collected on the backbone devices of Shanghai and their related ports. The data is as follows: the average flow velocity of the outgoing traffic components from Beijing to Shanghai is 120 Gbps; the average flow velocity of the incoming traffic components is 80 Gbps.
[0124] S05. Based on the core devices of Beijing and the core devices of Shanghai, obtain the shortest path between the devices through Dijkstra's algorithm. Convert the devices to the shortest path between provinces. The forward path (the path from Beijing to Shanghai) and the reverse path (the path from Shanghai to Beijing) will be obtained. The forward path uses the data of the outgoing traffic components, and the reverse path uses the data of the incoming traffic components. The data is as follows: the path from Beijing to Shanghai (the average flow velocity of the traffic components is 120 Gbps): Beijing -> Anhui -> Shanghai, the path from Shanghai to Beijing (the average flow velocity of the traffic components is 80 Gbps): Shanghai -> Anhui -> Beijing.
[0125] S06. Give a direct connection suggestion for the situation where the average flow velocity of the traffic components exceeds 100 Gbps (threshold, configurable) and the connection between provinces is non-direct. Since the average outgoing flow velocity from Beijing to Shanghai is 120 Gbps and Beijing to Shanghai needs to pass through Anhui, which is a non-direct connection situation, a direct connection suggestion needs to be given in the source province Beijing and the target province Shanghai of the traffic components.
[0126] S07. Distribute the traffic components in Step 4 to the link traffic data between provinces according to the inter-provincial path conditions. The link traffic utilization rate is obtained by dividing the traffic data by the link bandwidth. The following is an example: The inter-provincial path from Beijing to Shanghai is non-direct, Beijing -> Anhui -> Shanghai. Distribute the 120 Gbps traffic component from Beijing to Shanghai to the two paths of Beijing -> Anhui and Anhui -> Shanghai. According to the method in 3, the relay link bandwidth from Beijing to Anhui is 100 G. The average flow velocity of a single segment of traffic, 60 Gbps, divided by the link bandwidth of 100 G gives a traffic utilization rate of 60%, which exceeds 50% (threshold, configurable). Expansion suggestions are given for the source province Beijing and the target province Anhui of the link. Similarly, according to the method in 3, the relay link bandwidth from Anhui to Shanghai is 200 G. The average flow velocity of a single segment of traffic, 60 Gbps, divided by the link bandwidth of 200 G gives a traffic utilization rate of 30%, which does not exceed 50% (threshold, configurable), and no expansion suggestions are generated.
[0127] Based on the same inventive concept, the present invention also proposes a link precise expansion analysis device based on SNMP and Netflow. The implementation of this device can refer to the implementation of the above method, and the repeated parts will not be elaborated. The term "module" used hereinafter can be a combination of software and / or hardware that realizes a predetermined function. Although the device described in the following embodiments is preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0128] Figure 3 is a schematic structural diagram of the link precise expansion analysis device based on SNMP and Netflow of the present invention. As Figure 3 shown, the device includes:
[0129] A configuration data acquisition module 110, which acquires configuration data such as regular expressions of each province and its provincial core devices in the plane according to the selected plane;
[0130] A relay link data acquisition module 120, which obtains the provincial core devices according to the regular expressions of the provincial core devices, and further obtains the inter-provincial relay link data;
[0131] A traffic component acquisition module 130, which obtains the traffic component data between provinces by collecting and analyzing data through Netflow;
[0132] A shortest path calculation module 140, which calculates the path information from province to province according to the shortest path of the provincial core devices;
[0133] A direct connection suggestion module 150, which gives a direct connection suggestion according to the traffic component data calculated in the traffic component acquisition module 130, where the average flow velocity of the traffic component exceeds the threshold and the connection between provinces is non-direct;
[0134] The flow distribution and utilization acquisition module 160 obtains the flow distribution of the link between provinces and the flow utilization of the link between provinces according to the path information between provinces, the average flow rate of the flow components and the inter-provincial relay circuit data;
[0135] The capacity expansion suggestion module 170 provides capacity expansion suggestions in the source province and the target province of the link when the relay link calculated in the traffic distribution and utilization acquisition module 160 exceeds the utilization threshold.
[0136] The method for acquiring configuration data in the configuration data acquisition module 110 is: acquiring from plane configuration data and node province configuration data, and the configuration data is manually maintained data.
[0137] The relay link data acquisition module 120 includes:
[0138] The core device judgment module matches the device name obtained by the collection. If the device name satisfies the provincial core device regular expression, it is the provincial core device.
[0139] The relay link acquisition module, based on the collected circuit data, determines that the link whose dual-end devices are both provincial core devices is an inter-provincial relay link.
[0140] The inter-provincial relay link data in the relay link acquisition module includes: circuit identification, local device identification, opposite device identification, local port name, opposite port name, metric, and bandwidth.
[0141] The flow component acquisition module 130 includes:
[0142] Define the module, and define the basic object and its object type first through address segment range, BGPASPATH regular expression, BGPCOMMUNITY, etc.
[0143] Netflow collection module: Netflow collection tags the traffic according to the custom basic object to obtain information such as device identification, port name, collection time, source network, target network, target address segment, packet rate, etc.
[0144] The province acquisition module can obtain the source province and the destination province according to the source network and the target network;
[0145] The traffic component acquisition module, the traffic information between the relevant networks belonging to the source province and the relevant networks belonging to the target province, is the traffic component between provinces.
[0146] The traffic distribution and utilization rate acquisition module 160 of the provincial route link traffic distribution is: total traffic from province to province / number of route hops, and the total traffic is evenly distributed among the provinces;
[0147] The calculation method of the inter-provincial link traffic utilization rate is: traffic / bandwidth.
[0148] It should be noted that although several modules of the link precise capacity expansion analysis device based on SNMP and Netflow are mentioned in the above detailed description, this division is only exemplary and not mandatory. In fact, according to the embodiments of the present invention, the features and functions of the two or more modules described above can be embodied in one module. Conversely, the features and functions of one module described above can be further divided and embodied by multiple modules.
[0149] Based on the foregoing inventive concept, as Figure 4 shown, the present invention also provides a computer device 200, including a memory 210, a processor 220, and a computer program 230 stored on the memory 210 and executable on the processor 220. When the processor 220 executes the computer program 230, the foregoing link precise capacity expansion analysis method based on SNMP and Netflow is implemented.
[0150] Based on the foregoing inventive concept, the present invention also provides a computer-readable storage medium, which stores a computer program for executing the foregoing link precise capacity expansion analysis method based on SNMP and Netflow.
[0151] The present invention intuitively displays data such as inter-provincial relay link traffic, metric values, and bandwidth; the present invention marks the provinces that need capacity expansion or are recommended for direct connection with stars for subsequent processing; the present invention intuitively displays the mutual access traffic and access paths of each province.
[0152] Although the spirit and principles of the present invention have been described with reference to several specific embodiments, it should be understood that the present invention is not limited to the specific embodiments disclosed, and the division of each aspect does not mean that the features in these aspects cannot be combined for benefits. This division is only for the convenience of expression. The present invention aims to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.
[0153] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.
[0154] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing device, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program code can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on the remote machine or server.
[0155] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0156] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0157] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0158] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, or a server of a distributed system, or a server incorporating a blockchain.
[0159] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution disclosed in this disclosure can be achieved, and no limitation is imposed herein.
[0160] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of this disclosure shall be included within the protection scope of this disclosure.
[0161] Regarding the limitations on the scope of protection of the present invention, those skilled in the art should understand that, based on the technical solutions of the present invention, various modifications or deformations that can be made by those skilled in the art without creative efforts are still within the scope of protection of the present invention.
Claims
1. A link accurate expansion analysis method based on SNMP and Netflow, It is characterized in that The method includes: S01. According to the selected plane, obtain configuration data such as regular expressions of each province and its provincial core devices in the plane; S02, obtaining the provincial core device according to the provincial core device regular expression, and then obtaining the inter-provincial relay link data; S03, obtain traffic composition data between provinces through Netflow collection and analysis data; S04, obtaining the province-to-province path information based on the shortest path calculation of the provincial core device; S05. According to the flow component data calculated in S03, if the average flow rate of the flow component exceeds the super threshold value and the province to province is not directly connected, a direct connection suggestion is given; S06. According to the province-to-province path information, the average flow rate of the traffic components and the inter-province relay circuit data, the flow distribution of the province-to-province link and the flow utilization rate of the province-to-province link are obtained; the flow distribution of the province-to-province link is: the total flow from province to province / the number of hops in the path, and the total flow is evenly distributed among the provinces; the flow utilization rate of the inter-province link is calculated as: flow / bandwidth; S07. When the relay link calculated in S06 exceeds the utilization threshold, a capacity expansion suggestion is given in the source province and the target province of the link.
2. According to the link accurate expansion analysis method based on SNMP and Netflow according to claim 1, It is characterized in that The method for obtaining the configuration data in S01 is: obtaining it from the plane configuration data and the node province configuration data, and the configuration data is manually maintained data.
3. According to the link accurate expansion analysis method based on SNMP and Netflow according to claim 1, It is characterized in that S02 includes: S021. Match the device name obtained by the collection. If the device name meets the provincial core device regular expression, the device is a provincial core device. S022. According to the collected circuit data, a link in which both end devices are provincial core devices is an inter-provincial relay link.
4. According to claim 3, the link accurate expansion analysis method based on SNMP and Netflow, It is characterized in that The inter-provincial relay link data in S022 includes: circuit identification, local device identification, opposite device identification, local port name, opposite port name, metric, and bandwidth.
5. According to claim 1, the link accurate expansion analysis method based on SNMP and Netflow, It is characterized in that The S03 includes: S031. The basic object and its object type will be defined first through address segment range, BGP ASPATH regular expression, BGP COUMMUNITY, etc. S032, Netflow collection tags the traffic according to the custom basic object, and obtains information such as device identification, port name, collection time, source network, target network, target address segment, packet rate, etc. S033. According to the source network and the target network, the source province and the target province can be obtained; S034. The traffic information between the relevant networks belonging to the source province and the relevant networks belonging to the target province is the traffic component between provinces.
6. A link accurate expansion analysis device based on SNMP and Netflow, It is characterized in that The device includes: The configuration data acquisition module acquires configuration data such as regular expressions of provinces and their provincial core devices in the plane according to the selected plane; The relay link data acquisition module obtains the provincial core device according to the provincial core device regular expression, and then obtains the inter-provincial relay link data; The traffic component acquisition module collects and analyzes data through Netflow to obtain traffic component data between provinces; The shortest path calculation module calculates the shortest path from province to province based on the provincial core device; The direct connection suggestion module gives a direct connection suggestion based on the flow component data calculated in the flow component acquisition module, if the average flow rate of the flow component exceeds the threshold and the province to province is not directly connected; The traffic distribution and utilization acquisition module obtains the traffic distribution of the province-to-province link and the traffic utilization of the province-to-province link based on the province-to-province path information, the average flow rate of the traffic components and the inter-province relay circuit data; the traffic distribution of the province-to-province link is: the total traffic from province to province / the number of hops, and the total traffic is evenly distributed among the provinces; the calculation method of the traffic utilization of the inter-province link is: traffic / bandwidth; The capacity expansion suggestion module gives capacity expansion suggestions in the source province and the target province of the link when the relay link calculated in the traffic distribution and utilization acquisition module exceeds the utilization threshold.
7. The link accurate expansion analysis device based on SNMP and Netflow according to claim 6, It is characterized in that The method for acquiring configuration data in the configuration data acquisition module is: acquiring from plane configuration data and node province configuration data, and the configuration data is manually maintained data.
8. The link accurate expansion analysis device based on SNMP and Netflow according to claim 6, It is characterized in that The relay link data acquisition module includes: The core device judgment module matches the device name obtained by the collection. If the device name satisfies the provincial core device regular expression, it is the provincial core device. The relay link acquisition module, based on the collected circuit data, determines that the link whose dual-end devices are both provincial core devices is an inter-provincial relay link.
9. The link accurate expansion analysis device based on SNMP and Netflow according to claim 8, It is characterized in that The inter-provincial relay link data in the relay link acquisition module includes: circuit identification, local device identification, opposite device identification, local port name, opposite port name, metric, and bandwidth.
10. The link accurate expansion analysis device based on SNMP and Netflow according to claim 6, It is characterized in that The flow component acquisition module includes: Define the module, address range, BGP ASPATH regularization, BGP COUMMUNITY, etc. to define the basic object and its object type; The Netflow collection module tags the traffic according to the custom basic object in Netflow collection to obtain information such as device identification, port name, collection time, source network, target network, target address segment, and packet speed; The module for obtaining the province to which it belongs can obtain the province to which the source belongs and the province to which the destination belongs according to the source network and the target network; The traffic component obtaining module: The traffic information between the relevant network belonging to the source province and the relevant network belonging to the target province is the traffic component between provinces.
11. A computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, when the processor executes the computer program, it implements the method according to any one of claims 1-5.
12. A computer-readable storage medium, characterized in that, the computer-readable storage medium stores a computer program for executing the method according to any one of claims 1-5.
Citation Information
Patent Citations
Large-scale IP network flow monitoring method and device
CN104518920A