Method, device, storage medium and electronic device for discovering network topology structure
The method simplifies network topology discovery by using network address planning and device logs to construct device and host connections, reducing costs and complexity without requiring SNMP support.
Patent Information
- Application Number
- CN202211670507.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-23
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-12-23
AI Technical Summary
In the prior art, network topology discovery has high cost and high requirements for technical personnel.
Use network address planning information to build connection relationships between device nodes, and filter out host nodes through device logs to form a network topology structure, avoiding dependence on communication protocols such as SNMP.
Reduces the cost of network topology discovery, improves network management efficiency and accuracy, and enables rapid location and failure of network equipment.
Smart Images

Figure CN116016197B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network security services, and particularly to a method, apparatus, storage medium, and electronic device for discovering a network topology structure. Background Art
[0002] The way of connecting between network devices is called "Network Topology". Network topology refers to the physical layout of interconnecting various devices with transmission media, especially the location of computers and how cables pass through them. When designing a network, the correct topology method should be selected according to the actual situation, and each topology structure has its own advantages and disadvantages. The main purpose of network topology discovery is to obtain and maintain the existence information of network nodes and the connection relationship information between them, and on this basis, draw the entire network topology diagram. Network administrators can quickly locate faulty nodes based on the topology diagram.
[0003] Currently, the commonly used methods for network topology discovery mainly include the following three: the network topology discovery method based on the SNMP protocol; the network topology discovery method based on general protocols; the network topology discovery method based on routing protocols. However, when actually discovering the network topology structure, it requires network devices to support and open the SNMP service or other relevant protocol communications. At the same time, it also requires network administrators to be familiar with the SNMP management information base (MIB) data of network devices, and have the ability to perform complex comparison, association, and fusion analysis on the obtained information. It also needs to be implemented on the basis of combining IT operation and maintenance monitoring functions. Its implementation cost is relatively high, and it has relatively high requirements for technical personnel. Summary of the Invention
[0004] The purpose of the embodiments of the present disclosure is to provide a method, apparatus, storage medium, and electronic device for discovering a network topology structure, so as to solve the problems of high implementation cost and high requirements for technical personnel in the prior art for realizing network topology structure discovery.
[0005] The embodiments of the present disclosure adopt the following technical solutions: A method for discovering a network topology structure, including: obtaining network address planning information; forming asset data according to the network address planning information, where the asset data at least includes multiple device nodes in the network topology structure; constructing the connection relationship between the device nodes according to the network address planning information; obtaining the device logs of the device nodes; creating multiple host nodes in the network topology structure according to the device logs; determining the connection relationship between the host nodes and the device nodes according to the network address planning information to form the network topology structure.
[0006] In some embodiments, the network address planning information at least includes network segment planning information and device planning information; wherein, the network segment planning information at least includes: network segment start address, network segment end address, gateway address, access switch device address, access switch device VLAN, address type; the device planning information at least includes: switch device VLAN, device address, network egress type.
[0007] In some embodiments, when there is a first device node with the network egress type being the Internet or a private network among all device nodes, after constructing the connection relationship between the device nodes according to the network address planning information, it further includes: creating a cloud node; constructing the connection relationship between the cloud node and the first device node.
[0008] In some embodiments, creating multiple host nodes in the network topology structure according to the device log includes: extracting the IP address from the device log; determining the host address according to the IP address and the network segment planning information, and creating the host node according to the host address.
[0009] In some embodiments, determining the connection relationship between the host node and the device node according to the network address planning information includes: determining the network segment to which the host address corresponding to the host node belongs according to the network segment planning information, establishing a network segment node corresponding to each network segment, constructing the connection relationship between the host node and the network segment node; constructing the connection relationship between the network segment node and the device node according to the network segment planning information; establishing the connection relationship between the host node and the device node according to the connection relationship between the host node and the network segment node and the connection relationship between the network segment node and the device node.
[0010] In some embodiments, constructing the connection relationship between the network segment node and the device node according to the network segment planning information includes: sequentially searching for the device node adjacent to each network segment node in the priority order of the access switch device address, the access switch device VLAN, and the gateway address; establishing the connection relationship between the network segment node and the adjacent device node.
[0011] In some embodiments, after determining the connection relationship between the host node and the device node according to the network address planning information to form the network topology, the method further includes: displaying the network topology in a preset manner; where the preset manner includes at least any one of the following: displaying the device node and the host node; displaying the device node and the cloud node; displaying the device node, the network segment node, and the cloud node; displaying the device node, the cloud node, and the host node; displaying the device node, the network segment node, the host node, and the cloud node.
[0012] An embodiment of the present disclosure further provides a network topology discovery device, including: a first acquisition module, configured to acquire network address planning information; a first configuration module, configured to form asset data according to the network address planning information, where the asset data includes at least multiple device nodes in the network topology; a first construction module, configured to construct the connection relationship between the device nodes according to the network address planning information; a second acquisition module, configured to acquire the device logs of the device nodes; a second configuration module, configured to create multiple host nodes in the network topology according to the device logs; a second construction module, configured to determine the connection relationship between the host node and the device node according to the network address planning information to form the network topology.
[0013] An embodiment of the present disclosure further provides a storage medium storing a computer program, characterized in that when the computer program is executed by a processor, the steps of the above-mentioned network topology discovery method are implemented.
[0014] An embodiment of the present disclosure further provides an electronic device, including at least a memory and a processor, where a computer program is stored on the memory, and when the processor executes the computer program on the memory, the steps of the above-mentioned network topology discovery method are implemented.
[0015] The beneficial effects of the embodiments of the present disclosure are as follows: By using the existing network address planning information to construct the connection relationship between device nodes in the network topology, and then using the device logs of the device nodes to screen out the host nodes connected to the network topology for connection relationship construction, it is not necessary to rely on communication protocols such as SNMP, and the network topology management capability can be quickly delivered on the basis of greatly reducing costs. Description of the Drawings
[0016] To more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present disclosure. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0017] Figure 1 It is a flowchart of the method for discovering the network topology structure in the first embodiment of the present disclosure;
[0018] Figure 2 It is a schematic diagram of the network topology structure in the first embodiment of the present disclosure;
[0019] Figure 3 It is a schematic structural diagram of the device for discovering the network topology structure in the second embodiment of the present disclosure;
[0020] Figure 4 It is a schematic structural diagram of the electronic device in the fourth embodiment of the present disclosure. Detailed implementation manners
[0021] Reference is made herein to the various aspects and features of the present disclosure with reference to the accompanying drawings.
[0022] It should be understood that various modifications can be made to the embodiments applied herein. Therefore, the above description should not be regarded as a limitation, but only as an example of the embodiments. Those skilled in the art will think of other modifications within the scope and spirit of the present disclosure.
[0023] The drawings included in the specification and constituting a part of the specification illustrate the embodiments of the present disclosure, and together with the general description of the present disclosure given above and the detailed description of the embodiments given below, are used to explain the principles of the present disclosure.
[0024] These and other features of the present disclosure will become apparent from the following description of the preferred forms of the embodiments given by way of non-limiting examples with reference to the accompanying drawings.
[0025] It should also be understood that although the present disclosure has been described with reference to some specific examples, those skilled in the art can surely implement many other equivalent forms of the present disclosure, which have the features as claimed and thus are all within the protection scope defined thereby.
[0026] When combined with the accompanying drawings, in view of the following detailed description, the above and other aspects, features and advantages of the present disclosure will become more obvious.
[0027] Specific embodiments of the present disclosure will be described hereinafter with reference to the accompanying drawings. However, it should be understood that the embodiments claimed are merely examples of the present disclosure, which can be implemented in various ways. Well-known and / or repetitive functions and structures are not described in detail to avoid obscuring the present disclosure with unnecessary or redundant details. Therefore, the specific structural and functional details claimed herein are not intended to be limiting, but are merely a basis and representative basis for the claims to teach those skilled in the art to use the present disclosure in substantially any suitable detailed structure in a variety of ways.
[0028] This specification may use the phrases "in one embodiment", "in another embodiment", "in yet another embodiment", or "in other embodiments", each of which may refer to one or more of the same or different embodiments according to the present disclosure.
[0029] The first embodiment of the present disclosure provides a method for discovering a network topology structure, which is mainly applied to a situation awareness and security operation platform. Network administrators perform security monitoring on devices in the network through the platform, and timely locate the positions of corresponding network devices when the network devices are attacked or malfunction, so as to perform corresponding processing. For regular user network administrators, they may not have professional operation and maintenance technologies. Even if the platform detects malicious attacks or fault situations, they may not be able to quickly and accurately locate the corresponding devices. Therefore, the platform can build and display an intuitive network topology structure, which can assist users in monitoring the device status and quickly locating the devices, and is beneficial to maintaining the security of network devices.
[0030] Figure 1 The flowchart of the discovery method provided in this embodiment is shown. As Figure 1 shown, the method at least includes steps S10 to S60:
[0031] S10, obtain network address planning information.
[0032] Network address planning information refers to the information formed when users allocate various network devices and network addresses and other information according to actual needs during the network planning process. During the construction of the physical network, each network device will be configured according to the content recorded in the network address planning information. The above configurations include, but are not limited to, connection relationship configuration between devices, network segment configuration of devices, port configuration, address type configuration, etc.
[0033] The network address planning information in this embodiment at least includes network segment planning information and device planning information. Among them, the network segment planning information is mainly used to record content such as the starting address of the network segment, the ending address of the network segment, the gateway address, the access switch device address, the access switch device VLAN, and the address type. It is a record of basic information such as network segments when users configure the network. For example, the starting address and ending address of the network segment are mainly used to indicate the network segment information assigned to each device; the gateway address is usually the address configured by the three-layer switch when implementing the gateway function; the access switch device address is the address of the two-layer switch accessing the corresponding network segment, enabling host devices that want to enter the network segment to access the network through this two-layer switch; the access switch device VLAN represents the corresponding VLAN port number when configuring the two-layer switch for the three-layer switch; the address type is used to record network types such as public network, private network, or default private network. The device planning information mainly includes content such as the switch device VLAN, device address, and network exit type, and is used to record the configurations of each device in the network itself. For example, the switch device VLAN is used to represent the two-point VLAN port number configured for the two-layer switch; the device address represents the address assigned to the device, and a device can have multiple device addresses at the same time, such as a three-layer switch or a firewall, etc.; the network exit type is used to represent the node type connected to the network exit of each device, which can include the Internet, a private network, or default none. When the network exit type of the device is the Internet or a private network, it means that it is connected to the corresponding Internet node or private network node, and when it is default none, it is connected to other network devices in the network topology.
[0034] S20. Generate asset data according to the network address planning information.
[0035] The solution of this embodiment is applied to the situation awareness and security operation platform. For the situation awareness and security operation platform, it usually has an asset configuration function, and each device in the network also belongs to a type of asset. After the platform obtains the network address planning information, it generates asset data for storage according to the specific content included in the network address planning information. Specifically, the asset data should at least include each device node used to form the network topology structure, mainly referring to devices such as switches and firewalls. The asset data also includes the configurations corresponding to each device node, such as the content included in the network address planning information such as device address and network segment allocation. It should be noted that the formation process of the asset data in this embodiment can be directly implemented using the existing asset management function module in the platform, as long as the corresponding network planning data is added when forming the device node.
[0036] S30. Construct the connection relationship between device nodes according to the network address planning information.
[0037] After the asset data is formed, the connection relationship between device nodes can be constructed according to various parameters recorded in the network address planning information. Specifically, the corresponding gateway address and the corresponding access device can be found from the network segment planning information according to the device address, and the connection relationship between the device node and the device node of its corresponding access device can be established to form a static network topology structure.
[0038] In some embodiments, if there is a first device node with an Internet or private network network exit type among the device nodes, a cloud node representing the Internet or private network can be correspondingly established, and the connection relationship between the first device node and the cloud node can be further established to implement the configuration of the network exit. It should be noted that the number of first device nodes can be one or more, and the number of first device nodes and the type of cloud nodes they are connected to can be correspondingly set according to actual network requirements to realize the use of the Internet or private network.
[0039] S40. Obtain the device logs of the device nodes.
[0040] Logs are information recorded by computer systems, devices, software, etc. under certain circumstances. The specific content depends on the source of the logs. For example, the operating system will record logs of information such as user logins and logouts; the firewall will record logs of messages such as acl passes and rejections of access control protocols; some systems will issue logs with warning messages when the system itself believes that some failures will occur. These logs usually carry network quintuple information (usually referring to the source IP address, source port, destination IP address, destination port, and transport layer protocol), and the IP addresses of which hosts or devices exist in the network environment can be obtained from the logs. When the device node is a device such as a switch, the device logs generated during its actual use also record information such as the IP addresses communicating or connected to the device node. Based on this, the host conditions connected to different device nodes can be known to realize a dynamic network topology and form a complete network topology structure.
[0041] In this embodiment, the platform can implement the process of collecting the device logs of the device nodes through the data collection management function module, or can also obtain the device logs through other functions of the platform. This embodiment does not limit this here.
[0042] S50. Create multiple host nodes in the network topology structure according to the device logs.
[0043] A host node refers to the device actually operated by a user in a network topology, such as a computer, mobile phone, printer, or server. The host node accesses the network by connecting to a device node. Therefore, the device node records information about the host nodes that access itself or communicate with itself. The platform can obtain the device logs accordingly from the device logs and create host nodes based on the information of the host nodes. Specifically, at least the IP addresses are recorded in the device logs, and these IP addresses can be those of host nodes or other device nodes. After the platform extracts the IP addresses from the device logs, it can screen out the IP addresses that do not belong to device nodes from all the extracted IP addresses according to the network segment planning information, and these IP addresses that do not belong to device nodes are the host addresses and belong to the host nodes connected to or communicating with this device node.
[0044] S60. Determine the connection relationship between the host node and the device node according to the network address planning information to form a network topology.
[0045] As the device actually used by the user, the host node can be connected to the network in real time as the number of platform users increases. It may be connected to different device nodes according to user needs and be assigned different IP addresses. And according to the access of the host node to the Internet or private network, its corresponding IP address may be recorded in the device logs of multiple device nodes. Therefore, when establishing the connection relationship between the host node and the device node, it is necessary to determine the device node actually accessed by the host node in combination with the network address planning information. After determining the connection relationship between the host node and the device node, the network topologies of dynamic devices and static devices can be formed, and the discovery of the complete network topology can be realized.
[0046] Specifically, when determining the connection relationship between the host node and the device node, first determine the network segment to which the host node belongs based on the host address (i.e., IP address) corresponding to the host node. In actual use, there may be multiple hosts belonging to the same network segment. Therefore, the repeated operations of multiple host nodes belonging to the same network segment when constructing the connection relationship can be simplified by establishing network segment nodes. It only needs to connect the host node to its corresponding network segment node, which also simplifies the display effect when finally presenting the network topology. Subsequently, determine the access device node corresponding to each network segment based on the access switch device address recorded in the network segment planning information, and establish the connection relationship between the network segment node belonging to this network segment and its corresponding device node to connect the network segment node to the network topology. Finally, the connection relationship between the host node and the device node can be established according to the connection relationship between the host node and the network segment node, and the connection relationship between the network segment node and the device node.
[0047] It should be understood that in some embodiments, when establishing the connection relationship between network segment nodes and device nodes, the device node closest to each network segment node can be searched in turn according to the priority order of access switch device address, access switch VLAN, and gateway address. This device node is the device node to which the network segment node is connected, and the connection relationship between the network segment node and the device node can be correspondingly established. Generally speaking, the access switch device address is used to indicate the address of the layer-2 switch accessing the corresponding network segment, that is, the address of the layer-2 switch to which all host devices connected to this network segment are actually connected. Therefore, this layer-2 switch is usually the device node closest to the network segment node. The access switch VLAN is similar to the access switch device address, both of which are used to indicate the devices and ports accessing the network segment. In the case where there is no layer-2 switch in the current network segment, the network segment node can also be directly connected to the layer-3 switch used as the gateway through the gateway address.
[0048] In some embodiments, after the network topology structure is formed, it can be displayed in the form of an image on the operation interface of the platform according to user requirements, providing the user with an intuitive and accurate network topology structure to help the user accurately understand each device and its connection relationship in the current network. When the platform detects a device failure or a network attack, the corresponding attacked or faulty device can be marked in the image to assist the user in quickly locating the device. Figure 2 A schematic diagram of a network topology structure is shown. In the figure, each device node (layer-3 switch, multiple layer-2 switches, firewall, traffic detection device, etc.) and its corresponding network configuration (including but not limited to device address, network segment address, port number, IP address, etc.) are shown, and it also includes cloud nodes (internet nodes), host nodes (PC, server) and their IP addresses, etc. It should be noted that Figure 2 the network segment nodes are not shown in the figure. When the number of host nodes is too large, the network segment nodes can actually be used to replace the host nodes and be connected under the layer-2 switch to simplify the schematic diagram of the network topology structure, or different nodes can be displayed according to user requirements.
[0049] When actually displaying the network topology structure, it can be carried out in a preset manner. The preset manner defined in this embodiment includes but is not limited to any one of the following:
[0050] (1) Display device nodes and host nodes;
[0051] (2) Display device nodes and cloud nodes;
[0052] (3) Display device nodes, network segment nodes, and cloud nodes;
[0053] (4) Display device nodes, cloud nodes, and host nodes;
[0054] (5) Display device nodes, network segment nodes, host nodes, and cloud nodes.
[0055] In this embodiment, the existing network address planning information is used to construct the connection relationships between device nodes in the network topology, and then the host nodes connected to the network topology are screened out from the device logs of the device nodes to construct the connection relationships, without the support of communication protocols such as SNMP, and the network topology management capabilities can be quickly delivered on the basis of greatly reducing costs.
[0056] The second embodiment of the present disclosure provides a discovery device for a network topology structure. The device can be installed in a situation awareness and security operation platform. Network administrators can perform security monitoring on the devices in the network through the platform, and locate the positions of the corresponding network devices in a timely manner when the network devices are attacked or malfunction, so as to perform corresponding processing. Figure 3 The structural schematic diagram of the discovery device provided in this embodiment is shown, which mainly includes: a first acquisition module 10 for acquiring network address planning information; a first configuration module 20 for forming asset data according to the network address planning information, and the asset data at least includes multiple device nodes in the network topology; a first construction module 30 for constructing the connection relationships between device nodes according to the network address planning information; a second acquisition module 40 for acquiring the device logs of the device nodes; a second configuration module 50 for creating multiple host nodes in the network topology according to the device logs; a second construction module 60 for determining the connection relationships between the host nodes and the device nodes according to the network address planning information to form a network topology structure.
[0057] It should be noted that each functional module provided in this embodiment can be an original functional module in the situation awareness and security operation platform, or a functional module formed after improving the original functional module. In actual implementation, modules with the same or similar functions can also be merged. For example, the first acquisition module and the second acquisition module can be merged into an acquisition module, and the first configuration module and the second configuration module can be merged into a configuration module, etc. This embodiment does not actually limit the number or naming of the functional modules. As long as there are modules that can implement the corresponding functions in the platform, it is sufficient.
[0058] Specifically, the network address planning information at least includes network segment planning information and device planning information; among them, the network segment planning information at least includes: network segment start address, network segment end address, gateway address, access switch device address, access switch device VLAN, address type; the device planning information at least includes: switch device VLAN, device address, network egress type.
[0059] In some embodiments, the discovery device may further include a cloud node configuration module ( Figure 3(not shown in the figure) is used to create a cloud node and establish a connection relationship between the cloud node and the first device node when there is a first device node with an Internet or private network network exit type among all device nodes.
[0060] In some embodiments, the second configuration module 50 is specifically configured to extract an IP address from device logs; determine a host address based on the IP address and network segment planning information, and create a host node based on the host address.
[0061] In some embodiments, the second construction module 60 is specifically configured to determine the network segment to which the host address corresponding to the host node belongs according to the network segment planning information, establish a network segment node corresponding to each network segment, and establish a connection relationship between the host node and the network segment node; construct a connection relationship between the network segment node and the device node according to the network segment planning information; establish a connection relationship between the host node and the device node according to the connection relationship between the host node and the network segment node and the connection relationship between the network segment node and the device node.
[0062] In some embodiments, the second construction module 60 is specifically configured to sequentially search for device nodes adjacent to each network segment node in the priority order of access switch device address, access switch VLAN, and gateway address; establish a connection relationship between the network segment node and the adjacent device node.
[0063] In some embodiments, the discovery device may further include a display module ( Figure 3 (not shown in the figure), which is mainly used to display the network topology structure in a preset manner; wherein, the preset manner includes at least any one of the following: displaying device nodes and host nodes; displaying device nodes and cloud nodes; displaying device nodes, network segment nodes, and cloud nodes; displaying device nodes, cloud nodes, and host nodes; displaying device nodes, network segment nodes, host nodes, and cloud nodes.
[0064] This embodiment uses the existing network address planning information to construct the connection relationship between device nodes in the network topology, and then uses the device logs of the device nodes to screen out the host nodes connected to the network topology for connection relationship construction, without the support of communication protocols such as SNMP, and can quickly deliver the network topology management capability on the basis of greatly reducing costs.
[0065] The third embodiment of the present disclosure provides a storage medium, which can be installed in the situation awareness and security operation platform, and is specifically a computer-readable medium, storing a computer program, which when executed by a processor implements the method provided by any embodiment of the present disclosure, including the following steps S31 to S36:
[0066] S31, obtain network address planning information;
[0067] S32. Form asset data according to the network address planning information, where the asset data at least includes multiple device nodes in the network topology structure;
[0068] S33. Construct the connection relationships between the device nodes according to the network address planning information;
[0069] S34. Obtain the device logs of the device nodes;
[0070] S35. Create multiple host nodes in the network topology structure according to the device logs;
[0071] S36. Determine the connection relationships between the host nodes and the device nodes according to the network address planning information to form the network topology structure.
[0072] Specifically, the network address planning information at least includes network segment planning information and device planning information; among them, the network segment planning information at least includes: network segment start address, network segment end address, gateway address, access switch device address, access switch device VLAN, address type; the device planning information at least includes: switch device VLAN, device address, network exit type.
[0073] When there is a first device node with the network exit type being the Internet or a private network among all device nodes, after the computer program is executed by the processor to construct the connection relationships between the device nodes according to the network address planning information, the processor also executes the following steps: create a cloud node; construct the connection relationship between the cloud node and the first device node.
[0074] When the computer program is executed by the processor to create multiple host nodes in the network topology structure according to the device logs, the processor specifically executes the following steps: extract the IP addresses from the device logs; determine the host addresses according to the IP addresses and the network segment planning information, and create the host nodes according to the host addresses.
[0075] When the computer program is executed by the processor to determine the connection relationships between the host nodes and the device nodes according to the network address planning information, the processor specifically executes the following steps: determine the network segment to which the host address corresponding to the host node belongs according to the network segment planning information, establish a network segment node corresponding to each network segment, construct the connection relationship between the host node and the network segment node; construct the connection relationship between the network segment node and the device node according to the network segment planning information; establish the connection relationship between the host node and the device node according to the connection relationship between the host node and the network segment node and the connection relationship between the network segment node and the device node.
[0076] When the computer program is executed by the processor to construct the connection relationship between the network segment nodes and the device nodes according to the network segment planning information, it is specifically executed by the processor as follows: sequentially search for the device nodes adjacent to each network segment node in the priority order of the access switch device address, the access switch device VLAN, and the gateway address; establish the connection relationship between the network segment nodes and the adjacent device nodes.
[0077] After the computer program is executed by the processor to determine the connection relationship between the host nodes and the device nodes according to the network address planning information to form the network topology structure, it is further executed by the processor as follows: display the network topology structure in a preset manner; where the preset manner includes at least any one of the following: display the device nodes and the host nodes; display the device nodes and the cloud nodes; display the device nodes, the network segment nodes, and the cloud nodes; display the device nodes, the cloud nodes, and the host nodes; display the device nodes, the network segment nodes, the host nodes, and the cloud nodes.
[0078] This embodiment uses the existing network address planning information to construct the connection relationship between the device nodes in the network topology, and then uses the device logs of the device nodes to filter out the host nodes connected to the network topology for connection relationship construction. Without the support of communication protocols such as SNMP, it can quickly deliver the network topology management ability on the basis of greatly reducing costs.
[0079] The fourth embodiment of the present disclosure provides an electronic device, which may have a situation awareness and security operation platform. The schematic structural diagram is as Figure 4 shown, and at least includes a memory 100 and a processor 200. A computer program is stored on the memory 100, and when the processor 200 executes the computer program on the memory 100, it implements the method provided in any embodiment of the present disclosure. Exemplarily, the computer program steps of the electronic device are as follows S41 to S46:
[0080] S41, obtain network address planning information;
[0081] S42, form asset data according to the network address planning information, and the asset data at least includes multiple device nodes in the network topology structure;
[0082] S43, construct the connection relationship between the device nodes according to the network address planning information;
[0083] S44, obtain the device logs of the device nodes;
[0084] S45, create multiple host nodes in the network topology structure according to the device logs;
[0085] S46. Determine the connection relationship between the host node and the device node according to the network address planning information to form the network topology structure.
[0086] Specifically, the network address planning information at least includes network segment planning information and device planning information; among them, the network segment planning information at least includes: network segment start address, network segment end address, gateway address, access switch device address, access switch device VLAN, address type; the device planning information at least includes: switch device VLAN, device address, network exit type.
[0087] In the case where there is a first device node with the network exit type being the Internet or a private network among all device nodes, after the processor executes the computer program for constructing the connection relationship between the device nodes according to the network address planning information stored in the memory, the following computer program is further executed: create a cloud node; construct the connection relationship between the cloud node and the first device node.
[0088] When the processor executes the computer program for creating multiple host nodes in the network topology structure according to the device log stored in the memory, the following computer program is specifically executed: extract the IP address from the device log; determine the host address according to the IP address and the network segment planning information, and create the host node according to the host address.
[0089] When the processor executes the computer program for determining the connection relationship between the host node and the device node according to the network address planning information stored in the memory, the following computer program is specifically executed: determine the network segment to which the host address corresponding to the host node belongs according to the network segment planning information, establish a network segment node corresponding to each network segment, and construct the connection relationship between the host node and the network segment node; construct the connection relationship between the network segment node and the device node according to the network segment planning information; establish the connection relationship between the host node and the device node according to the connection relationship between the host node and the network segment node and the connection relationship between the network segment node and the device node.
[0090] When the processor executes the computer program for constructing the connection relationship between the network segment node and the device node according to the network segment planning information, the following computer program is specifically executed: sequentially search for the device node adjacent to each network segment node in the priority order of the access switch device address, the access switch device VLAN, and the gateway address; establish the connection relationship between the network segment node and the adjacent device node.
[0091] After the processor executes the computer program stored in the memory to determine the connection relationship between the host node and the device node according to the network address planning information to form the network topology structure, the processor further executes the following computer program: displaying the network topology structure in a preset manner; wherein, the preset manner includes at least any one of the following: displaying the device node and the host node; displaying the device node and the cloud node; displaying the device node, the network segment node, and the cloud node; displaying the device node, the cloud node, and the host node; displaying the device node, the network segment node, the host node, and the cloud node.
[0092] This embodiment uses the existing network address planning information to construct the connection relationship between device nodes in the network topology, and then uses the device logs of the device nodes to filter out the host nodes connected to the network topology for connection relationship construction. Without the support of communication protocols such as SNMP, it can quickly deliver network topology management capabilities on the basis of greatly reducing costs.
[0093] The above has described multiple embodiments of the present disclosure in detail, but the present disclosure is not limited to these specific embodiments. Those skilled in the art can make various variations and modifications to the embodiments on the basis of the concept of the present disclosure, and these variations and modifications should fall within the scope of protection required by the present disclosure.
Claims
1. A method for discovering a network topology structure, characterized in that Including: Obtain network address planning information; Form asset data according to the network address planning information, where the asset data at least includes multiple device nodes in the network topology; Construct the connection relationships between the device nodes according to the network address planning information; Obtain the device logs of the device nodes; Create multiple host nodes in the network topology according to the device logs; Determine the connection relationships between the host nodes and the device nodes according to the network address planning information to form the network topology; The network address planning information at least includes network segment planning information and device planning information; where The network segment planning information at least includes: network segment start address, network segment end address, gateway address, access switch device address, access switch device VLAN, address type; The device planning information at least includes: switch device VLAN, device address, network exit type; Among them, the determining the connection relationships between the host nodes and the device nodes according to the network address planning information includes: Determine the network segment to which the host address corresponding to the host node belongs according to the network segment planning information, establish a network segment node corresponding to each network segment, and construct the connection relationships between the host node and the network segment nodes; Construct the connection relationships between the network segment nodes and the device nodes according to the network segment planning information; Establish the connection relationships between the host nodes and the device nodes according to the connection relationships between the host nodes and the network segment nodes and the connection relationships between the network segment nodes and the device nodes.
2. The discovery method according to claim 1, wherein In the case where there is a first device node with the network exit type being the Internet or a private network among all device nodes, after constructing the connection relationships between the device nodes according to the network address planning information, it further includes: Create a cloud node; Construct the connection relationship between the cloud node and the first device node.
3. The discovery method according to claim 2, wherein The creating multiple host nodes in the network topology according to the device logs includes: Extract IP addresses from the device logs; Determine the host addresses according to the IP addresses and the network segment planning information, and create the host nodes according to the host addresses.
4. The discovery method according to claim 2, characterized in that The constructing the connection relationships between the network segment nodes and the device nodes according to the network segment planning information includes: Sequentially search for the device nodes adjacent to each network segment node in the priority order of the access switch device address, the access switch device VLAN, and the gateway address; Establish the connection relationships between the network segment nodes and the adjacent device nodes.
5. The discovery method according to claim 4, characterized in that, After determining the connection relationships between the host nodes and the device nodes according to the network address planning information to form the network topology, it further includes: Display the network topology in a preset manner; Among them, the preset manner at least includes any one of the following: Display the device nodes and the host nodes; Display the device nodes and the cloud nodes; Display the device nodes, the network segment nodes, and the cloud nodes; Display the device nodes, the cloud nodes, and the host nodes; Show the device nodes, the network segment nodes, the host nodes, and the cloud nodes.
6. A discovery device for a network topology structure, characterized in that, Including: A first acquisition module, configured to acquire network address planning information; The network address planning information at least includes network segment planning information and device planning information; wherein, the network segment planning information at least includes: network segment start address, network segment end address, gateway address, access switch device address, access switch device VLAN, address type; the device planning information at least includes: switch device VLAN, device address, network egress type; A first configuration module, configured to form asset data according to the network address planning information, and the asset data at least includes multiple device nodes in the network topology structure; A first construction module, configured to construct the connection relationship between the device nodes according to the network address planning information; A second acquisition module, configured to acquire the device logs of the device nodes; A second configuration module, configured to create multiple host nodes in the network topology structure according to the device logs; A second construction module, configured to determine the connection relationship between the host nodes and the device nodes according to the network address planning information to form the network topology structure; Wherein, determining the connection relationship between the host nodes and the device nodes according to the network address planning information includes: Determining the network segment to which the host address corresponding to the host node belongs according to the network segment planning information, establishing a network segment node corresponding to each network segment, and constructing the connection relationship between the host node and the network segment node; Constructing the connection relationship between the network segment node and the device node according to the network segment planning information; Establishing the connection relationship between the host node and the device node according to the connection relationship between the host node and the network segment node and the connection relationship between the network segment node and the device node.
7. A storage medium stores a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method for discovering a network topology structure according to any one of claims 1 to 5.
8. An electronic device, at least comprising a memory and a processor, wherein a computer program is stored on the memory, characterized in that, When the processor executes the computer program on the memory, it implements the steps of the method for discovering a network topology structure according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method, system and apparatus for discovering network function virtualization (NFV) resource pool topology
CN106533712A
Dynamic network topological graph generation method based on logs and graphs and system thereof, processing equipment and storage medium
CN113904921A